<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search multiple hosts with one search string in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42722#M10009</link>
    <description>&lt;P&gt;You can also use the regex command to pipe a field through a regular expression. &lt;/P&gt;

&lt;P&gt;For example: &lt;/P&gt;

&lt;P&gt;index=bro sourcetype=bro_conn &lt;BR /&gt;
|  regex dest_ip="/(^127.)|(^192.168.)|(^10.)|(^172.1[6-9].)|(^172.2[0-9].)|(^172.3[0-1].)|(^::1$)|(^[fF][cCdD])/"&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 22:21:28 GMT</pubDate>
    <dc:creator>bliscuit</dc:creator>
    <dc:date>2020-09-29T22:21:28Z</dc:date>
    <item>
      <title>Search multiple hosts with one search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42714#M10001</link>
      <description>&lt;P&gt;How would I search multiple hosts with one search string?&lt;/P&gt;

&lt;P&gt;I have 6 hosts and want the results for all:&lt;/P&gt;

&lt;P&gt;Search String:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="rdpg"
( 2222222 dest_port="") OR (1111111 src_port="") OR ( 1111111 src_ip="") OR (2222222 dest_ip="")
| eval disconnect_time=if(match(_raw,"2222222"),_time,null()) 
| eval connect_time=if(match(_raw,"1111111"),_time,null())
| eval Ephemeral=if(isnotnull(disconnect_time),dest_port,Ephemeral) 
| eval Ephemeral=if(isnotnull(connect_time),src_port,Ephemeral)
| stats min(connect_time) as Connect max(disconnect_time) as Disconnect min(src_ip) as "Source IP" max(dest_ip) as "Destin ip" by Ephemeral
| eval Seconds=Disconnect-Connect | fieldformat Seconds=strftime('Seconds', "%s") 
| eval "Total Time"=tostring(Seconds,"duration") 
| where Seconds &amp;gt; 300 
| search Connect=* Disconnect=*
| appendpipe [stats sum(Seconds) as "Total Seconds" ]
| convert timeformat="%a %b-%d %Y "at" %H:%M:%S" ctime(Connect) ctime(Disconnect)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hosts= Srv004 Srv005 Srv181 Srv192 Srv142 Srv181&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2013 19:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42714#M10001</guid>
      <dc:creator>Xe03kfp</dc:creator>
      <dc:date>2013-02-25T19:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: Search multiple hosts with one search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42715#M10002</link>
      <description>&lt;P&gt;AND operators could help in this situation&lt;/P&gt;

&lt;P&gt;host="srv004" AND host="srv005" AND .....&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2013 19:33:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42715#M10002</guid>
      <dc:creator>herkalurk</dc:creator>
      <dc:date>2013-02-25T19:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: Search multiple hosts with one search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42716#M10003</link>
      <description>&lt;P&gt;Didn't work&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2013 19:35:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42716#M10003</guid>
      <dc:creator>Xe03kfp</dc:creator>
      <dc:date>2013-02-25T19:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: Search multiple hosts with one search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42717#M10004</link>
      <description>&lt;P&gt;Sorry, I should have said OR ...&lt;/P&gt;

&lt;P&gt;host="srv004" OR host="srv005" OR .....&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2013 19:49:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42717#M10004</guid>
      <dc:creator>herkalurk</dc:creator>
      <dc:date>2013-02-25T19:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Search multiple hosts with one search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42718#M10005</link>
      <description>&lt;P&gt;If you were to do that report on each host individually, in the time frame you're searching, you got results from each host?  I only want to make sure that the fact you're only seeing 2 hosts isn't because the others don't have data.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2013 20:46:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42718#M10005</guid>
      <dc:creator>herkalurk</dc:creator>
      <dc:date>2013-02-25T20:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Search multiple hosts with one search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42719#M10006</link>
      <description>&lt;P&gt;How could you use wildcards in server name to get groups of host without typing each one in?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2015 15:56:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42719#M10006</guid>
      <dc:creator>msackett</dc:creator>
      <dc:date>2015-08-07T15:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: Search multiple hosts with one search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42720#M10007</link>
      <description>&lt;P&gt;host="srv00*"&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 19:50:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42720#M10007</guid>
      <dc:creator>hari2139</dc:creator>
      <dc:date>2016-12-22T19:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: Search multiple hosts with one search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42721#M10008</link>
      <description>&lt;P&gt;host=srv00* will give all hosts matching the wildcard.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2017 00:32:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42721#M10008</guid>
      <dc:creator>prabhu77749</dc:creator>
      <dc:date>2017-01-18T00:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Search multiple hosts with one search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42722#M10009</link>
      <description>&lt;P&gt;You can also use the regex command to pipe a field through a regular expression. &lt;/P&gt;

&lt;P&gt;For example: &lt;/P&gt;

&lt;P&gt;index=bro sourcetype=bro_conn &lt;BR /&gt;
|  regex dest_ip="/(^127.)|(^192.168.)|(^10.)|(^172.1[6-9].)|(^172.2[0-9].)|(^172.3[0-1].)|(^::1$)|(^[fF][cCdD])/"&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:21:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42722#M10009</guid>
      <dc:creator>bliscuit</dc:creator>
      <dc:date>2020-09-29T22:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: Search multiple hosts with one search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42723#M10010</link>
      <description>&lt;P&gt;Thanks! This helped. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 14:57:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/42723#M10010</guid>
      <dc:creator>ryhluc01</dc:creator>
      <dc:date>2019-01-29T14:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Search multiple hosts with one search string</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/696332#M236666</link>
      <description>&lt;P&gt;should use OR condition to include all hosts....host="srv004" OR host="srv005" OR&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 01:33:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-multiple-hosts-with-one-search-string/m-p/696332#M236666</guid>
      <dc:creator>rammeduru</dc:creator>
      <dc:date>2024-08-15T01:33:23Z</dc:date>
    </item>
  </channel>
</rss>

