Splunk Search

How to combine multiple search raw strings in a single query

rkishoreqa
Communicator

Hi, 

 

I need to do search with multiple raw strings within a single query.  When I search these strings separately, I am able to get the results.  But when I combine these it is not giving the results and ending with 'No results found'. 

The below three queries are working fine.

  • sourcetype="States*"  *Karnataka*
  • sourcetype="States*"  *Tamil Nadu*
  • sourcetype="States*"  *Mumbai*

When I execute the below query I am getting 'No results found' comment. 

  • sourcetype="States*"  *Karnataka*  *Tamil Nadu*  *Mumbai*

Can anyone through some light on this, thanks in advance.

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

SPL inserts an implicit AND between each search term.  To search for optional terms, insert an explicit OR.

sourcetype="States*" ("*Karnataka*" OR "*Tamil Nadu*" OR "*Mumbai*")

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

SPL inserts an implicit AND between each search term.  To search for optional terms, insert an explicit OR.

sourcetype="States*" ("*Karnataka*" OR "*Tamil Nadu*" OR "*Mumbai*")

 

---
If this reply helps you, Karma would be appreciated.

saravanan90
Contributor

Please use "OR" inbetween the searches..

sourcetype="States*"  (*Karnataka*  OR  *Tamil Nadu* OR  *Mumbai*)

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...