Hi all
I have a combined lookup data with a fields containing various values like aaa acc aan, and more. I'm looking to find a single value for 'aan' from the 'source' field specifically when 'source' has ss Ann ’or css.
Could you please help me construct the correct Splunk query for this?"
Please provide some sample anonymised events