Hi @mclane41,
I tested your issue on an 8.2 version and the issue is present.
This means that this is a known issue solved with the new versions, so the only solution is to upgrade Splunk.
Ciao.
Giuseppe
I work with the version Enterprise 8.2.0
Hi @mclane41,
I tested your issue on an 8.2 version and the issue is present.
This means that this is a known issue solved with the new versions, so the only solution is to upgrade Splunk.
Ciao.
Giuseppe
Which version of Splunk are you using? The first query works for me in 9.0.0.1.