Splunk Search

Search for multiple keywords.

ykmohank
New Member

Hi,

I want to do a search having multiple strings.

Example: Consider,I am looking for SearchKey1 and SerachKey2

In SQL i will write something like this

Select * from Table_Name where ColumnName like '%SearchKey1%' and ColumnName like '%SerachKey2%'

IN SQL the above query returns me all the rows having both search keys SearchKey1 and SearchKey2 in it.

I want to achieve similiar kind of search in SPLUNK. Please help me with appropriate code.

Tags (3)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi ykmohank,

as always docs is your friend, read this guide for SQL users.

cheers, MuS

MuS
SplunkTrust
SplunkTrust

but I give you some hint:

source=_Name ColumnName="*SearchKey1*" ColumnName="*SearchKey2*"
or
index=_Name ColumnName="*SearchKey1*" ColumnName="*SearchKey2*"

adminpulse
Loves-to-Learn Lots

its not working

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...