Splunk Search

How to merge two Splunk searches into one?

pratheeshrajan1
New Member

Hi Team,

search sourcetype=my_logs source.item_id=34324234324| stats count by event_type

and

search sourcetype=my_logs source.folder_id=4324324324 | stats count by event_type

Can someone help me to merge the above two searches to a single one please

Tags (1)
0 Karma

LuiesCui
Communicator
sourcetype=my_logs source.item_id=34324234324 AND source.folder_id=4324324324| stats count by event_type 

you don't have to put a "search" at the front.

0 Karma

jeffland
SplunkTrust
SplunkTrust

You mean like this?

sourcetype=my_logs source.item_id=34324234324 OR source.folder_id=4324324324 | stats count by event_type
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...