Hi Team
I am looking to get two different field values in a single query in Splunk, example, I have two different country codes and would like to get both their values
Request.countrycode=EU
Request.country=SW
“Or” command is not working for this, any suggestions team ?
Are you using "OR" - this has to be all in caps for it to work.
Request.countrycode=EU OR Request.country=SW
Thanks, but how to get the stats count of these two values?
Stats count by Request.countrycode, Request.country
is not returning any values
Can you share some anonymised sample events and the current search you are working with, and some idea of what you are trying to get out of it?