Answer by warren for Searching for specific values in Splunk query

For readibility, try using IN():

index=sne host=nwbsnep* sourcetype IN(sne_CAS_elilogs,sne_CMS_elilogs) Service.Operation IN("A","B","C","D","E","F","G","H")

The issue seems to have been, though, that in your second parenthesized set of ORs, you had this:

OR "Service.Operation"="D "OR "Service.Operation"="E" OR "Service.Operation"="F" 

In SPL, the OR has to be separated from what it’s or’ing by at least one space

You had one slammed against a quote mark

from User warren – Stack Overflow https://stackoverflow.com/questions/58915438/searching-for-specific-values-in-splunk-query/73129443#73129443
via IFTTT