<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Iterate search over multiple field values in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Iterate-search-over-multiple-field-values/m-p/506463#M141702</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222843"&gt;@Sam1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can use filed= value1 OR filed=value2 and so on in the search. You can always configure the alert to send an email for each result OR group of results.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anilchaithu_0-1593403878428.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9366i4876E1D408D59F9B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anilchaithu_0-1593403878428.png" alt="anilchaithu_0-1593403878428.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jun 2020 04:11:30 GMT</pubDate>
    <dc:creator>anilchaithu</dc:creator>
    <dc:date>2020-06-29T04:11:30Z</dc:date>
    <item>
      <title>Iterate search over multiple field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Iterate-search-over-multiple-field-values/m-p/506457#M141700</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've created a search which is based on 1 field value but I need the search to run over many field values.&amp;nbsp; Rather than many repeating lines.&lt;/P&gt;&lt;P&gt;What is the best way to do this?&amp;nbsp; I know what the field values are before the search too.&lt;/P&gt;&lt;P&gt;It will be an alert where if 1 or more field values match the end criteria, an email is sent.&amp;nbsp; I only want 1 email, not 1 for every field value.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 03:56:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Iterate-search-over-multiple-field-values/m-p/506457#M141700</guid>
      <dc:creator>Sam1</dc:creator>
      <dc:date>2020-06-29T03:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Iterate search over multiple field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Iterate-search-over-multiple-field-values/m-p/506463#M141702</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222843"&gt;@Sam1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can use filed= value1 OR filed=value2 and so on in the search. You can always configure the alert to send an email for each result OR group of results.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anilchaithu_0-1593403878428.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9366i4876E1D408D59F9B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="anilchaithu_0-1593403878428.png" alt="anilchaithu_0-1593403878428.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 04:11:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Iterate-search-over-multiple-field-values/m-p/506463#M141702</guid>
      <dc:creator>anilchaithu</dc:creator>
      <dc:date>2020-06-29T04:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: Iterate search over multiple field values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Iterate-search-over-multiple-field-values/m-p/506469#M141705</link>
      <description>&lt;P&gt;To give some more detail of my search, it takes the field value and look at the past hour of data, compares that to the past week of data to get the percent difference.&amp;nbsp; Then show result where diff &amp;gt; x.&lt;/P&gt;&lt;P&gt;This needs to done for each field value though and I don't know how to do that without a lot of evals, addtotals, etc.&amp;nbsp; I want to be able to do a nice clean short search regardless of the field value, and pass in the field value.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 05:21:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Iterate-search-over-multiple-field-values/m-p/506469#M141705</guid>
      <dc:creator>Sam1</dc:creator>
      <dc:date>2020-06-29T05:21:57Z</dc:date>
    </item>
  </channel>
</rss>

