Answer by warren for Splunk -> two fields not equal to each other

Why not do:

index=* source=*.csv Requester=* NOT Requester="Requested For"

This ensures there is a Requester field present, and that it is not equal to "Requested For"

from User warren – Stack Overflow https://stackoverflow.com/questions/74310836/splunk-two-fields-not-equal-to-each-other/74319434#74319434
via IFTTT