Typically, that is done like this
index=A OR index=B | stats values(*) as * by field
but that requires and exact match of 'field' in each index. So what you'll need to do is massage
field into something Splunk can compare.
index=A OR index=B | eval newfield=<something that normalizes field> | stats values(*) as * by newfield
or use rex to normalize the field
index=A OR index=B | rex field=field "(?<newfield>something)" | stats values(*) as * by newfield
I'll leave the "something" up to you since only you know how to compare the data in each index.
If this reply helps you, Karma would be appreciated.