Monitoring Splunk

How to use multiple AND & OR condition?

fivesevenfeeeet
Engager

Hello, I'm looking to create a query that helps to search the following conditions.

For example, get the address for

1. John from Spain 

2. Jane from London 

3. Terry from France

My current methodology is to run each query one by one for each examples.

index IN ( sampleIndex)
John AND Spain
| stats name, country, address

After running the above query, I run for the next example.
index IN ( sampleIndex)
Jane AND London
| stats name, country, address

Running 1 query for 1 example will become tedious if I have thousand of examples to go through.

It is possible to get some help on creating query that help to run similar logic like the following,

index IN ( sampleIndex)
Jane AND London OR
John AND Spain OR 
Terry AND France
| stats name, country, address

Sorry if my question isn't clear.

Tags (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @fivesevenfeeeet,

you can use parenthesis in boolean conditions to define rules:

index IN (sampleIndex) ((Jane London) OR (John Spain) OR (Terry France))
| stats name, country, address

the AND condition isn't mandatory in searches (it's mandatory in eval).

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @fivesevenfeeeet,

you can use parenthesis in boolean conditions to define rules:

index IN (sampleIndex) ((Jane London) OR (John Spain) OR (Terry France))
| stats name, country, address

the AND condition isn't mandatory in searches (it's mandatory in eval).

Ciao.

Giuseppe

fivesevenfeeeet
Engager

Life saver, thank you 🙂

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...