Splunk Search

How to add multiple field in a single search

jaibalaraman
Path Finder

Hi 

How to write spl search query by adding multiple field in single search 

 

Field 1 - contain data like authorization " Write or Read " 

Field 2 - contain user id details like " @abc.com , user1, user 2, 

Question 

How to write a spl query 

Index =testing ("write" AND " @abc.com" ) 

spl query to add multiple filed which contain " write " AND "@abc.com" when these condition satisfied an alert has to been sent 

Tags (1)
0 Karma

norbertt911
Communicator

May I misunderstand your question, but it's simple:

index= testing field1="write" field2="*@abc.com"

|table field1, field2, ....

if "@abc.com"  is a user name and not a domain (as I assume) you do not need to put the wildcard (*) before. If you put it, it will result in every user with @abc.com. Like, user1@abc.com, user2@abc.com...

alternative:

index=testing | stats count by field1 field2 | search field1="write" AND field2"*@abc.com"

Regards,

0 Karma

jaibalaraman
Path Finder

yes i can see the output. However  the search returns based on the string mentioned in the bracket  and also additionally it returns most of other user id 

example - @abc.com , @test.com , testing.@test.co

0 Karma

jaibalaraman
Path Finder

Hi please

find the below image 

jaibalaraman_0-1716463297677.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please paste the text (not an image) of the search into code block (otherwise, it is too small to be read easily)

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please share some of the events whish are being returned incorrectly (anonymised appropriately)

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try

Index=testing ("write" AND " @abc.com" ) 

What results do you get?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...