Splunk Search

How to get multiple search condition on a single query?

Anushuba
New Member

Hi Team

I have this requirement .Could you please help me on it .Here is my question

  1. I wanted to get result for PageUrls based on top 5 http status code. In single query I should get URL1,URL2 .... URL10 & its 500 (top 5 ),502(top 5), 503(top 5 ) w.r.t URL's
  2. With above condition - I should get the URL & its UserID but here the index is same but sourcetype is different along with condition where status code=500

Please assist me kindly on this

0 Karma

P_vandereerden
Splunk Employee
Splunk Employee

Better late than never: 

Sample data would be helpful here.  The request is a bit confusing since you seem to want the top 5 urls per status code, but your URL count stops at 10. With 3 status codes, the top 5 could go to 15, right?

For the second point, what UserID  would that be? Presumably each URL could be hit by multiple users, and the top 5 codes for each URL would differ per user. 

Paul van der Eerden,
Breaking software for over 20 years.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...