<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limited Search to 2 Categories in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147243#M41157</link>
    <description>&lt;P&gt;Well with condition 'like(category,"IBC Allow%")', it's capturing 'IBC Allow' 'IBC Allows'  etc basically anything that starts with 'IBC Allow'. To capture other categories, you need to added conditions for those as well (e.g. category="IBC Allow*" OR category="softwhitelist" OR category="shopping"). If the no of categories to be included is high but categories to be excluded is small, you can use 'NOT' to exclude them instead of providing big inclusion list.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jul 2014 13:58:24 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2014-07-17T13:58:24Z</dc:date>
    <item>
      <title>Limited Search to 2 Categories</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147238#M41152</link>
      <description>&lt;P&gt;The search below is taking anything that contains IBC Allow in the category and repurposing it to a new Category. Only thing is, I'm not able to capture the IBC Allows stuff as well from the category and repurpose it to the new Category. How can I accomplish this?&lt;/P&gt;

&lt;P&gt;index=proxysg sourcetype=proxysg | eval Category=case(like(category,"IBC Allow%"),"IBC",1=1,"Non-IBC") | search Category=IBC | timechart per_second(eval(round(if(Category="IBC",src_bytes,0)*8/1024/1024,2))) AS IBC_Traffic_Mb by GW&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:06:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147238#M41152</guid>
      <dc:creator>jaywilwk</dc:creator>
      <dc:date>2020-09-28T17:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Search to 2 Categories</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147239#M41153</link>
      <description>&lt;P&gt;Your search would be simpler and more efficient if you started it with:&lt;/P&gt;

&lt;P&gt;index=proxysg sourcetype=proxysg Category="IBC Allow*"&lt;/P&gt;

&lt;P&gt;Then the subsequent search would not be necessary.&lt;/P&gt;

&lt;P&gt;It's not clear to me exactly what you are trying to do.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 13:27:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147239#M41153</guid>
      <dc:creator>reed_kelly</dc:creator>
      <dc:date>2014-07-17T13:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Search to 2 Categories</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147240#M41154</link>
      <description>&lt;P&gt;Based on the filters you've applied, I guess the search cab be simplified as follow:&lt;/P&gt;

&lt;P&gt;index=proxysg sourcetype=proxysg category="IBC Allow*" | timechart per_second(eval(round(src_bytes*8/1024/1024,2))) AS IBC_Traffic_Mb by GW&lt;/P&gt;

&lt;P&gt;What do you mean by " capture the IBC Allows stuff as well from the category"? There are some special information present in field category which you want to display?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:06:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147240#M41154</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2020-09-28T17:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Search to 2 Categories</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147241#M41155</link>
      <description>&lt;P&gt;In the Category field with a capital "C", there are multiple categories for instance: IBC Allow, IBC Allows, Non-IBC, softwhitelist, shopping, etc... What I'm trying to do is grab all of the IBC Allow and IBC Allows stuff and put them into one category. My current search only grabs IBC Allow; it doesn't grab both of them.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 13:32:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147241#M41155</guid>
      <dc:creator>jaywilwk</dc:creator>
      <dc:date>2014-07-17T13:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Search to 2 Categories</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147242#M41156</link>
      <description>&lt;P&gt;How about:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=proxysg sourcetype=proxysg | eval Category=if(category like "IBC All%", "IBC","Non-IBC") | ...rest of your search...
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 17 Jul 2014 13:51:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147242#M41156</guid>
      <dc:creator>wpreston</dc:creator>
      <dc:date>2014-07-17T13:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Search to 2 Categories</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147243#M41157</link>
      <description>&lt;P&gt;Well with condition 'like(category,"IBC Allow%")', it's capturing 'IBC Allow' 'IBC Allows'  etc basically anything that starts with 'IBC Allow'. To capture other categories, you need to added conditions for those as well (e.g. category="IBC Allow*" OR category="softwhitelist" OR category="shopping"). If the no of categories to be included is high but categories to be excluded is small, you can use 'NOT' to exclude them instead of providing big inclusion list.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 13:58:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147243#M41157</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-07-17T13:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Search to 2 Categories</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147244#M41158</link>
      <description>&lt;P&gt;the like condition isn't capturing IBC Allow and IBC Allows; it's only capturing IBC Allow. I've done a search to compare the results and it's not capturing both. It's only capturing IBC Allow.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 14:02:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147244#M41158</guid>
      <dc:creator>jaywilwk</dc:creator>
      <dc:date>2014-07-17T14:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Search to 2 Categories</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147245#M41159</link>
      <description>&lt;P&gt;Per definition of LIKE it should [ like(category,"IBC Allow%") where % is wildcard character]. Try the search that I provided earlier and see if that's matching both 'IBC Allow' and 'IBC Allows'&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 14:36:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147245#M41159</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-07-17T14:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Search to 2 Categories</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147246#M41160</link>
      <description>&lt;P&gt;It didn't work. It's still not capturing the IBC Allows. It's only capturing IBC Allow.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2014 15:22:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147246#M41160</guid>
      <dc:creator>jaywilwk</dc:creator>
      <dc:date>2014-07-18T15:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Search to 2 Categories</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147247#M41161</link>
      <description>&lt;P&gt;If you run following, does it returns rows with category="IBC Allow" only or both?&lt;/P&gt;

&lt;P&gt;index=proxysg sourcetype=proxysg category="IBC Allow*"&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2014 15:27:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147247#M41161</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-07-18T15:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Search to 2 Categories</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147248#M41162</link>
      <description>&lt;P&gt;If I run this it will return results back for IBC Allow and IBC Allows.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2014 15:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Limited-Search-to-2-Categories/m-p/147248#M41162</guid>
      <dc:creator>jaywilwk</dc:creator>
      <dc:date>2014-07-18T15:58:11Z</dc:date>
    </item>
  </channel>
</rss>

