<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: complex conditional search in Security</title>
    <link>https://community.splunk.com/t5/Security/complex-conditional-search/m-p/710229#M18303</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276009"&gt;@intosplunk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;let me understand: how do you set variable1/2/3: using a dropdown or based on a condition inside the search?&lt;/P&gt;&lt;P&gt;If based on a dropdown, you can insert the different searches in the dropdown values.&lt;/P&gt;&lt;P&gt;If based on a condition, you should share your searches to understand how to build your complex search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jan 2025 07:54:05 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2025-01-30T07:54:05Z</dc:date>
    <item>
      <title>complex conditional search</title>
      <link>https://community.splunk.com/t5/Security/complex-conditional-search/m-p/710228#M18302</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hey Splunkers,&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm trying to create a conditional search that will run on the same index but will have different search terms according to a variable I have that can have one of three values.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;It is supposed to be something like that:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;index = my_index&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;variable = 1/2/3&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;if variable=1 then run search1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;if&amp;nbsp;variable=2 then run search2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;if&amp;nbsp;variable=3 then run search3&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;i tried multiple ways but they didn't work so im trying to get some help here&lt;/SPAN&gt;&lt;span class="lia-unicode-emoji" title=":grimacing_face:"&gt;😬&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 07:49:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/complex-conditional-search/m-p/710228#M18302</guid>
      <dc:creator>intosplunk</dc:creator>
      <dc:date>2025-01-30T07:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: complex conditional search</title>
      <link>https://community.splunk.com/t5/Security/complex-conditional-search/m-p/710229#M18303</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276009"&gt;@intosplunk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;let me understand: how do you set variable1/2/3: using a dropdown or based on a condition inside the search?&lt;/P&gt;&lt;P&gt;If based on a dropdown, you can insert the different searches in the dropdown values.&lt;/P&gt;&lt;P&gt;If based on a condition, you should share your searches to understand how to build your complex search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 07:54:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/complex-conditional-search/m-p/710229#M18303</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-30T07:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: complex conditional search</title>
      <link>https://community.splunk.com/t5/Security/complex-conditional-search/m-p/710232#M18304</link>
      <description>&lt;P&gt;i just tried doing it in a dashboad&amp;nbsp;&lt;SPAN&gt;and insert the different searches in a dropdown values and used the token after a search and it worked. thank you very much.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 08:08:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/complex-conditional-search/m-p/710232#M18304</guid>
      <dc:creator>intosplunk</dc:creator>
      <dc:date>2025-01-30T08:08:07Z</dc:date>
    </item>
  </channel>
</rss>

