Splunk Search

Limitation on number of boolean clauses within search string


Is there a limitation on the number of search boolean clauses (i.e. OR, AND) within a search string?

For example | search 'user1' OR 'user2' OR 'user3' OR ... 'user180'

It seems like the color of OR changes from orange to black after a certain number.

(I know need to figure out a way to shorten string due to blah, blah..)

0 Karma



I don't think there is a limit of boolean clauses you will reach easily. After a while the "syntax highlighting function" simply gives up to highlight the "OR" 's appropriately.

But you really need to figure out a way to shorten the string.
I already found a solution for you. Lookup Tables!


0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...