<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to combine multiple search raw strings in a single query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-search-raw-strings-in-a-single-query/m-p/538785#M152340</link>
    <description>&lt;P&gt;Please use "OR" inbetween the searches..&lt;/P&gt;&lt;P&gt;sourcetype="States*"&amp;nbsp; (*Karnataka*&amp;nbsp; OR&amp;nbsp; *Tamil Nadu* OR&amp;nbsp; *Mumbai*)&lt;/P&gt;</description>
    <pubDate>Fri, 05 Feb 2021 15:13:29 GMT</pubDate>
    <dc:creator>saravanan90</dc:creator>
    <dc:date>2021-02-05T15:13:29Z</dc:date>
    <item>
      <title>How to combine multiple search raw strings in a single query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-search-raw-strings-in-a-single-query/m-p/538783#M152339</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to do search with multiple raw strings within a single query.&amp;nbsp; When I search these strings separately, I am able to get the results.&amp;nbsp; But when I combine these it is not giving the results and ending with 'No results found'.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The below three queries are working fine.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;sourcetype="States*"&amp;nbsp; *Karnataka*&lt;/LI&gt;&lt;LI&gt;sourcetype="States*"&amp;nbsp; *Tamil Nadu*&lt;/LI&gt;&lt;LI&gt;sourcetype="States*"&amp;nbsp; *Mumbai*&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;When I execute the below query I am getting 'No results found' comment.&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;sourcetype="States*"&amp;nbsp; *Karnataka*&amp;nbsp; *Tamil Nadu*&amp;nbsp; *Mumbai*&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Can anyone through some light on this, thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 15:12:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-search-raw-strings-in-a-single-query/m-p/538783#M152339</guid>
      <dc:creator>rkishoreqa</dc:creator>
      <dc:date>2021-02-05T15:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to combine multiple search raw strings in a single query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-search-raw-strings-in-a-single-query/m-p/538785#M152340</link>
      <description>&lt;P&gt;Please use "OR" inbetween the searches..&lt;/P&gt;&lt;P&gt;sourcetype="States*"&amp;nbsp; (*Karnataka*&amp;nbsp; OR&amp;nbsp; *Tamil Nadu* OR&amp;nbsp; *Mumbai*)&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 15:13:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-search-raw-strings-in-a-single-query/m-p/538785#M152340</guid>
      <dc:creator>saravanan90</dc:creator>
      <dc:date>2021-02-05T15:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to combine multiple search raw strings in a single query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-search-raw-strings-in-a-single-query/m-p/538786#M152341</link>
      <description>&lt;P&gt;SPL inserts an implicit &lt;FONT face="courier new,courier"&gt;AND&lt;/FONT&gt; between each search term.&amp;nbsp; To search for optional terms, insert an explicit &lt;FONT face="courier new,courier"&gt;OR&lt;/FONT&gt;.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;sourcetype="States*" ("*Karnataka*" OR "*Tamil Nadu*" OR "*Mumbai*")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 15:17:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-search-raw-strings-in-a-single-query/m-p/538786#M152341</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-05T15:17:12Z</dc:date>
    </item>
  </channel>
</rss>

