Thank you somesoni2,
Your answer seems to have worked best for me and returns results as I needed. Apparently, 'sid' is not extracted automatically by Splunk, so I had to use the second suggestion.
Thanks to everyone for looking into this.
... View more