<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk query - multiple values from a field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/552967#M156964</link>
    <description>&lt;P&gt;Logical &lt;U&gt;OR&lt;/U&gt; if the intention is to include both "Rad Users" and "Fad Users" in output.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=wineventlog NewObjectDN="*OU=blue*" (OldObjectDN=*"Rad Users"* OR OldObjectDN=*"Fad Users"*) signature_id=4147&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 May 2021 15:12:50 GMT</pubDate>
    <dc:creator>yuanliu</dc:creator>
    <dc:date>2021-05-25T15:12:50Z</dc:date>
    <item>
      <title>Splunk query - multiple values from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/552963#M156962</link>
      <description>&lt;P&gt;Hi everyone. I'm trying to get this query going&amp;nbsp; with one search but I can't seem to do that. I can only get it to work when I separate into two queries. Here are the two queries.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Query1:&lt;/P&gt;&lt;P&gt;index=wineventlog NewObjectDN="*OU=blue*" OldObjectDN=*"Rad Users"* signature_id=4147&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Query2:&lt;/P&gt;&lt;P&gt;index=wineventlog NewObjectDN="*OU=blue*" OldObjectDN=*"Fad Users"* signature_id=4147&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the Field OldObjectDN has multiple values I'm trying to combine into one search. What would the proper syntax be?&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 15:06:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/552963#M156962</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2021-05-25T15:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query - multiple values from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/552965#M156963</link>
      <description>&lt;P&gt;You should try&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=wineventlog NewObjectDN="*OU=blue*" OldObjectDN IN (*"Rad Users"*, *"Fad Users"*) signature_id=4147&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 15:11:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/552965#M156963</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-05-25T15:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query - multiple values from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/552967#M156964</link>
      <description>&lt;P&gt;Logical &lt;U&gt;OR&lt;/U&gt; if the intention is to include both "Rad Users" and "Fad Users" in output.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=wineventlog NewObjectDN="*OU=blue*" (OldObjectDN=*"Rad Users"* OR OldObjectDN=*"Fad Users"*) signature_id=4147&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 15:12:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/552967#M156964</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2021-05-25T15:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query - multiple values from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553038#M156980</link>
      <description>&lt;P&gt;HI Soutamo, If I use your suggestion I get other values of the oldobjectDN that don't match "Rad Users" or "Fad Users".&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want the search result to ONLY give me events when the OldObjectDN contains either of those two values.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 00:19:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553038#M156980</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2021-05-26T00:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query - multiple values from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553040#M156981</link>
      <description>&lt;P&gt;Because the value "Sad Users" is being returned as well.&lt;/P&gt;&lt;P&gt;Trying to only return these values:&lt;/P&gt;&lt;P&gt;Rad Users&lt;BR /&gt;Fad Users&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 00:33:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553040#M156981</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2021-05-26T00:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query - multiple values from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553059#M156990</link>
      <description>&lt;P&gt;Yuanliu,&lt;/P&gt;&lt;P&gt;I'm trying to include either values but not both values.&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 05:57:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553059#M156990</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2021-05-26T05:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query - multiple values from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553064#M156994</link>
      <description>&lt;P&gt;If I understand right, you want to implement XOR not OR operation?&lt;/P&gt;&lt;P&gt;As Splunk haven't XOR on SPL (SPL2 have it?) you must write it with NOT AND. In your case it should work like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=wineventlog NewObjectDN="*OU=blue*" NOT (OldObjectDN=*"Rad Users"* AND OldObjectDN=*"Fad Users"*) signature_id=4147&lt;/LI-CODE&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 06:07:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553064#M156994</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-05-26T06:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query - multiple values from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553066#M156995</link>
      <description>&lt;P&gt;Can you illustrate input data and how the desired output will look like?&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 06:10:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553066#M156995</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2021-05-26T06:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query - multiple values from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553078#M157001</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=wineventlog NewObjectDN="*OU=blue*" (OldObjectDN=*"Rad Users"* OR OldObjectDN=*"Fad Users"*) AND NOT (OldObjectDN=*"Rad Users"* AND OldObjectDN=*"Fad Users"*) signature_id=4147&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 26 May 2021 06:52:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553078#M157001</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-26T06:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query - multiple values from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553158#M157023</link>
      <description>&lt;P&gt;Sure. Suppose I have this:&lt;/P&gt;&lt;P&gt;Field:&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;OldObjectDN&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Possible values:&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;OU=Rad Users&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;OU=Fad Users&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;OU=Sad Users&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;OU=Bad Users&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;OU=Mad Users&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;I only want the search to return events only if &lt;FONT color="#00FF00"&gt;OldobjectDN&lt;/FONT&gt; has the values for &lt;FONT color="#00FF00"&gt;Rad User&lt;/FONT&gt; OR &lt;FONT color="#00FF00"&gt;Fad Users&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 14:29:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553158#M157023</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2021-05-26T14:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query - multiple values from a field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553163#M157025</link>
      <description>&lt;P&gt;I got it.&amp;nbsp;&lt;BR /&gt;I had to do it this way&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(OldObjectDN=*"OU=Rad Users"*) OR (OldObjectDN=*"OU=Fad Users"*)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate the help from both of you.&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 14:44:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-query-multiple-values-from-a-field/m-p/553163#M157025</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2021-05-26T14:44:55Z</dc:date>
    </item>
  </channel>
</rss>

