Splunk Search

how to search by too deferent champs

aalaa
Path Finder

Hello ,

how to search by two different champs ? I try "OR" but not result

Thanks

Tags (1)
0 Karma

nickhills
Ultra Champion

I'm not sure what you mean by 'champ', but if you mean 'field' or 'conditions':

search index=main my_field=alpha OR my_field=bravo

To write this more verbosely (and not necessary but may help with comprehension) this is the same as:

search (index=main AND (my_field=alpha OR my_field=bravo))

If my comment helps, please give it a thumbs up!
0 Karma

DMohn
Motivator

Can you please post the SPL query you used? Your question is a bit unclear...

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...