Hello Splunk Community,
I would really appreciate any guidance. I become a bit more familiar with Splunk, but at this moment nothing I have tried has worked. I basically need to know where a value is being logged between two different fields. This is the scenario:
1. If 0 is the count for value (employeeID) between pdf and CSV - dont show.
2. When value (employeeId) count > 0 need to know if its logged in either the pdf or CSV
Assuming that PDF and CSV are two different fieldnames and not the value of a fieldname
your search
|eval source=coalesce(PDF,CSV,NA)
|stats count by employeeID,source
|where count > 0
Assuming that PDF and CSV are two different fieldnames and not the value of a fieldname
your search
|eval source=coalesce(PDF,CSV,NA)
|stats count by employeeID,source
|where count > 0