Splunk Search

Limitation on number of boolean clauses within search string

jcart11entergy
Engager

Is there a limitation on the number of search boolean clauses (i.e. OR, AND) within a search string?

For example | search 'user1' OR 'user2' OR 'user3' OR ... 'user180'

It seems like the color of OR changes from orange to black after a certain number.

(I know need to figure out a way to shorten string due to blah, blah..)

0 Karma

horsefez
Motivator

@jcart11entergy

I don't think there is a limit of boolean clauses you will reach easily. After a while the "syntax highlighting function" simply gives up to highlight the "OR" 's appropriately.

But you really need to figure out a way to shorten the string.
I already found a solution for you. Lookup Tables!

http://docs.splunk.com/Documentation/Splunk/7.1.2/SearchReference/Lookup

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...