Splunk Search

How do I create a query to look at multiple sources and destinations at one time?

millionz4184
New Member

What I am looking for is how to look at multiple sources and destinations in one query. In our enterprise environment, our servers are hosted offsite, and sometimes, I need to check the logs on multiple sources, and/or multiple destinations from the same source, or vice-versa. Is there a query that I can use that will facilitate that for me?

0 Karma
1 Solution

FrankVl
Ultra Champion

What have you tried so far and what issues are you running in to? Also, if you could provide some samples of the data you are looking at and then describe the desired outcome, that would certainly help.

In general (but since your question is a bit vague this may not be entirely relevant for what you are looking for), looking at multiple possible values for a certain field can be done in multiple ways. For instance by using OR operators: src=A OR src=B or by using wildcards src=10.10.*

View solution in original post

0 Karma

FrankVl
Ultra Champion

What have you tried so far and what issues are you running in to? Also, if you could provide some samples of the data you are looking at and then describe the desired outcome, that would certainly help.

In general (but since your question is a bit vague this may not be entirely relevant for what you are looking for), looking at multiple possible values for a certain field can be done in multiple ways. For instance by using OR operators: src=A OR src=B or by using wildcards src=10.10.*

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...