Splunk Search

How to display two different logs through a search ....

dilstn
Explorer

I have a two logs which i need to display them ...

Mar 27, 2013 1:21:43 AM json from session : country name => "India"..........
Mar 27, 2013 1:21:43 AM Authentication : username => "Shiva".........

So i need to display this both things in search ....

this is not working [ source="logs/catalina.out" json from session AND Authentication ]
this spl is not working .... can u guide me ...plz.....

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You want to use OR, not AND - AND will look for events matching both filters, OR will look for events matching at least one.

Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...