Hello,
I'm training on splunk, I need help.
I have an invoice list, extracted via this query :
sourcetype="*_invoice"
| where in (id,350,128,307)
| table id invoice ProductType
Result :
350 261313851 phone
128 261313851 screen
307 538601320 aquarium
.....
But I have to exclude invoice number 261313851 because it contains id = 350.
How can I do please ? foreach and condition if ?
| Foreach invoice [eval status_invoice=if(id!=350, "ok", "ko")]
| where status_invoice= "ok"?
Thank you in advance for your help.
Regards,
vita86
... View more