Monitoring Splunk

How to use multiple AND & OR condition?

fivesevenfeeeet
Engager

Hello, I'm looking to create a query that helps to search the following conditions.

For example, get the address for

1. John from Spain 

2. Jane from London 

3. Terry from France

My current methodology is to run each query one by one for each examples.

index IN ( sampleIndex)
John AND Spain
| stats name, country, address

After running the above query, I run for the next example.
index IN ( sampleIndex)
Jane AND London
| stats name, country, address

Running 1 query for 1 example will become tedious if I have thousand of examples to go through.

It is possible to get some help on creating query that help to run similar logic like the following,

index IN ( sampleIndex)
Jane AND London OR
John AND Spain OR 
Terry AND France
| stats name, country, address

Sorry if my question isn't clear.

Tags (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @fivesevenfeeeet,

you can use parenthesis in boolean conditions to define rules:

index IN (sampleIndex) ((Jane London) OR (John Spain) OR (Terry France))
| stats name, country, address

the AND condition isn't mandatory in searches (it's mandatory in eval).

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @fivesevenfeeeet,

you can use parenthesis in boolean conditions to define rules:

index IN (sampleIndex) ((Jane London) OR (John Spain) OR (Terry France))
| stats name, country, address

the AND condition isn't mandatory in searches (it's mandatory in eval).

Ciao.

Giuseppe

fivesevenfeeeet
Engager

Life saver, thank you 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...