Splunk now has an "IN" operator. So you can simply add the following to your search: CAR_MAKE IN (BMW, Volkswagon, Ford) If your search values have spaces, it will need to be wrapped in quotations. E.g: CAR_MAKE IN (BMW, Volkswagon, "Mercedes Benz", Ford) I know its late, but hopefully it can help people looking for it now. Also, you may want to correct the spelling of Volkswagen 🙂
... View more