hey thanks for answer looks like its not working, let me more clear about the problem,
One event has info what i need say FiledA which i extracted using splunk from raw data , will have valuses like trans1 ,trans2.... And ALSO say one value like REST , AND filedB which i extracted will have again tans1.trans2....AND say NOTSET , so date will be like Flied A entries which has REST , as a value , will be having m trans1..etc in FliedB
siminalry NOTSET in filed value will have values of trans1 etc in FiledA
So here am only intrested in trasn1,trans2...
... View more