Mydata is like below where the customerNumber can come like CustomerNumber or customernumber or CUSTOMERNUMBER AND isoCountryCode can come as IsoCountryCode, ISOCountryCode or any other combination. Now during field extraction Splunk considers all these fields as seperate. though while writing query i want to consider all these fields as one. Environment = prod-dmz-usch01 | API = testapi| RequestURI = /test/v5/tesdt/10-12345?customerNumber=01-12345&isoCountryCode=US | ProxyRequestFlowName = testDetails-OpenAPIv3GetVerb. My query is as below: index=test sourcetype="testsamples" testapi "ProxyRequestFlowName = testDetails-OpenAPIv3GetVerb" | search isocountrycode=US OR isoCountryCode=US -- this seems to be taking care of multiple values but it is not a good idea to write each field here, how to handle all scenario's ? | bucket _time span="24h" | chart count by customerNumber where count in top100 -- i am able to give only one value of customer number here , how can i handle all use cases ?
... View more