Splunk Search

input lookup aaa.csv fieldA=staff and fieldA=contractors |stats count

Communicator

Hi,

How can I extract 2 values from fieldA in a lookup and ignore the rest then count as total

0 Karma
1 Solution

Influencer

Try:

| inputlookup aaa.csv where fieldA IN ("staff", "contractors") |stats count

View solution in original post

Influencer

Try:

| inputlookup aaa.csv where fieldA IN ("staff", "contractors") |stats count

View solution in original post

Communicator

Thank you,

0 Karma