Dashboards & Visualizations

How to add two filter criteria in one search query

aditsss
Motivator

Hi Everyone,

I have two search queries with two filter criteria's 

1st query:

index=abc ns=xyz app_name=sd "ARC EVENT RECEIVED FROM SOURCE"| rex "RID:(?<RID>(\w+-){4}\w+)-(?<sourceagent>\w+-\w+)"
| stats count, by sourceagent,RID
| rename sourceagent as "Source"|fields RID Source

2nd query

index=abc ns=xyz app_name=sd"ARC SUCCESSFULLY UPDATED RESPONSE BACK TO SOURCE OR SF"| rex "RID:(?<RID>(\w+-){4}\w+)-(?<sourceagent>\w+-\w+)"
| stats count, by sourceagent,RID
| rename sourceagent as "Source"|fields RID Source

Since the search is same for both only the filter criteria is different like "ARC EVENT RECEIVED FROM SOURCE" and "ARC SUCCESSFULLY UPDATED RESPONSE BACK TO SOURCE OR SF".

How can I make it a single query with two filter criteria.

Can someone guide me on that.

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
index=abc ns=xyz app_name=sd "ARC EVENT RECEIVED FROM SOURCE" OR "ARC SUCCESSFULLY UPDATED RESPONSE BACK TO SOURCE OR SF"| rex "RID:(?<RID>(\w+-){4}\w+)-(?<sourceagent>\w+-\w+)"
| stats count, by sourceagent,RID
| rename sourceagent as "Source"|fields RID Source

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
index=abc ns=xyz app_name=sd "ARC EVENT RECEIVED FROM SOURCE" OR "ARC SUCCESSFULLY UPDATED RESPONSE BACK TO SOURCE OR SF"| rex "RID:(?<RID>(\w+-){4}\w+)-(?<sourceagent>\w+-\w+)"
| stats count, by sourceagent,RID
| rename sourceagent as "Source"|fields RID Source
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...