Splunk Search

How to merge two Splunk searches into one?

pratheeshrajan1
New Member

Hi Team,

search sourcetype=my_logs source.item_id=34324234324| stats count by event_type

and

search sourcetype=my_logs source.folder_id=4324324324 | stats count by event_type

Can someone help me to merge the above two searches to a single one please

Tags (1)
0 Karma

LuiesCui
Communicator
sourcetype=my_logs source.item_id=34324234324 AND source.folder_id=4324324324| stats count by event_type 

you don't have to put a "search" at the front.

0 Karma

jeffland
SplunkTrust
SplunkTrust

You mean like this?

sourcetype=my_logs source.item_id=34324234324 OR source.folder_id=4324324324 | stats count by event_type
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...