Hi,
I have a lookup with 2 fields, (device and IP) either of which can be used to log in to Splunk as the 'host' field. How can I compare both against the host field?
The ultimate aim is to pull back the last time the device logged in to Splunk, either via the device or the IP field.
I see at least two options: