Deployment Architecture

Search for to different subtypes

sympatiko
Communicator

Hi,

I want to search for any "virus" event in a two different subtype. Is it possible?

Thanks,

Tags (2)
1 Solution

somesoni2
Revered Legend

You can try like this

(index=A1 sourcetype=S1 type=traffic,subtype=forward) OR (index=A2 sourcetype=S3 type=utm,subtype=virus) | search <<your condition/filter/criteria to find virus>>

Where A1-S1 and A2-S2 are index-sourcetype combination for different subtype

View solution in original post

somesoni2
Revered Legend

You can try like this

(index=A1 sourcetype=S1 type=traffic,subtype=forward) OR (index=A2 sourcetype=S3 type=utm,subtype=virus) | search <<your condition/filter/criteria to find virus>>

Where A1-S1 and A2-S2 are index-sourcetype combination for different subtype

kml_uvce
Builder

What do you mean by subtype ? is this event type ?

kamal singh bisht
0 Karma

sympatiko
Communicator

Yes. That's what I mean.

0 Karma

Ayn
Legend

That depends completely on what eventtypes you have, what your definitions are for "virus events", and a number of other factors. Please provide more details with log samples and fields, and we'll stand a better chance of helping you.

0 Karma

sympatiko
Communicator

I want to manage logging from my fortigate firewall. There are two subtypes where fortigate is detecting a virus type of event. First is coming from "type=traffic,subtype=forward" and the other one is from "type=utm,subtype=virus" . I want to search for any virus from those two different subtypes? Is it possible?

Thanks,

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...