Splunk Search

Search within 2 entries

Ikanui123
New Member

Hello,

I want to search for an entry that contains UsersController#update and with the following entry that contain current_user='32'.

If I search it independently I got search results. But if I do both I get nothing.

Is anyone has an idea of the search that I have to do?

Thanks a lot!

Tags (2)
0 Karma

Ayn
Legend
 current_user="32" OR "UsersController#Update"
0 Karma

Ikanui123
New Member

thanks for replying, just as I said when searching for

current_user='32' "UsersController#update"

nothing is returned, since its not in the same entry. Thanks.

0 Karma

bwooden
Splunk Employee
Splunk Employee

Are you wanting events that have either or that have both? If either, the query would be current_user='32' OR "UsersController#update" For both, it would be current_user='32' "UsersController#update"

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...