Hi,
I am trying to include a condition where splunk needs to ignore when it two different fields has the same values.
Any suggestions?
Post your search if possible.
I would assume adding something like this at the end of your search
...|more search| where field1 != field2
That gives results where the two fields are not equal. Hope this helps.
Thanks,
Raghav
Post your search if possible.
I would assume adding something like this at the end of your search
...|more search| where field1 != field2
That gives results where the two fields are not equal. Hope this helps.
Thanks,
Raghav
There is also one more condition. Final result must find common Plugin_ID between (earliest=-180d@d latest= -30d@d) and ((earliest=-35@d latest= now)