Splunk Search

How to add multiple field in a single search

jaibalaraman
Path Finder

Hi 

How to write spl search query by adding multiple field in single search 

 

Field 1 - contain data like authorization " Write or Read " 

Field 2 - contain user id details like " @abc.com , user1, user 2, 

Question 

How to write a spl query 

Index =testing ("write" AND " @abc.com" ) 

spl query to add multiple filed which contain " write " AND "@abc.com" when these condition satisfied an alert has to been sent 

Tags (1)
0 Karma

norbertt911
Communicator

May I misunderstand your question, but it's simple:

index= testing field1="write" field2="*@abc.com"

|table field1, field2, ....

if "@abc.com"  is a user name and not a domain (as I assume) you do not need to put the wildcard (*) before. If you put it, it will result in every user with @abc.com. Like, user1@abc.com, user2@abc.com...

alternative:

index=testing | stats count by field1 field2 | search field1="write" AND field2"*@abc.com"

Regards,

0 Karma

jaibalaraman
Path Finder

yes i can see the output. However  the search returns based on the string mentioned in the bracket  and also additionally it returns most of other user id 

example - @abc.com , @test.com , testing.@test.co

0 Karma

jaibalaraman
Path Finder

Hi please

find the below image 

jaibalaraman_0-1716463297677.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please paste the text (not an image) of the search into code block (otherwise, it is too small to be read easily)

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please share some of the events whish are being returned incorrectly (anonymised appropriately)

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try

Index=testing ("write" AND " @abc.com" ) 

What results do you get?

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...