Splunk Dev

How can I "or" with a Pivot?

daniel333
Builder

All,

I'd like to alert on process which have Netcat or nmap running for quick notable event. I can get one or the other. But not really both in the single query. I can't seem to find any sort of "OR" for the pivot language.

| pivot Application_State Processes values(process) AS "process" SPLITROW dest AS dest FILTER process startsWith nc*

Any ideas?

Tags (1)
0 Karma

dkeck
Influencer
0 Karma

dkeck
Influencer

if it helped please accept the question 🙂

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...