Splunk Search

Is it possible to have a joined search with condition A in the first search OR condition B in the second search?

New Member

Is it possible to have a joined search with condition A in the first search OR condition B in the second search?

0 Karma

Ultra Champion

Retrieve events from the index

index=exostar (sourcetype=Exostar_File Comments=Comm ) OR (source=ExostarAudit_IFED "Comm WBS"=true)

I don't understand the intention of join , how about this?
Events that match either of the two conditions are searched.

0 Karma

New Member

second search is a subsearch

0 Karma

New Member

index="exostar" sourcetype="Exostar_File" Comments=Comm
| JOIN type=left UserEmail [search index=ifed source=ExostarAudit_IFED "Comm WBS"=true ]

I want all events where Comments=Comm OR "Comm WBS"=true ]

0 Karma

Builder

Almost certainly - can you give us a sample query you're working with? Hard to give the best answer otherwise

0 Karma