Hi,
I have a search and if within an event, I have two values that I want to tag to the same field, what will be the likely method to use? Example:
12/17/14 12:23:34 AM Name=abc........Name=qwe
thks
Set "KV_MODE" to "auto": http://docs.splunk.com/Documentation/Splunk/6.2.3/Knowledge/Createandmaintainsearch-timefieldextract...