Monitoring Splunk

How to use multiple AND & OR condition?

fivesevenfeeeet
Engager

Hello, I'm looking to create a query that helps to search the following conditions.

For example, get the address for

1. John from Spain 

2. Jane from London 

3. Terry from France

My current methodology is to run each query one by one for each examples.

index IN ( sampleIndex)
John AND Spain
| stats name, country, address

After running the above query, I run for the next example.
index IN ( sampleIndex)
Jane AND London
| stats name, country, address

Running 1 query for 1 example will become tedious if I have thousand of examples to go through.

It is possible to get some help on creating query that help to run similar logic like the following,

index IN ( sampleIndex)
Jane AND London OR
John AND Spain OR 
Terry AND France
| stats name, country, address

Sorry if my question isn't clear.

Tags (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @fivesevenfeeeet,

you can use parenthesis in boolean conditions to define rules:

index IN (sampleIndex) ((Jane London) OR (John Spain) OR (Terry France))
| stats name, country, address

the AND condition isn't mandatory in searches (it's mandatory in eval).

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @fivesevenfeeeet,

you can use parenthesis in boolean conditions to define rules:

index IN (sampleIndex) ((Jane London) OR (John Spain) OR (Terry France))
| stats name, country, address

the AND condition isn't mandatory in searches (it's mandatory in eval).

Ciao.

Giuseppe

fivesevenfeeeet
Engager

Life saver, thank you 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...