# Multiple filter in query

**URL:** <https://community.graylog.org/t/multiple-filter-in-query/16083>\
**Category:** Graylog Central (peer support)\
**Created:** [June 26, 2020, 6:16am UTC](https://community.graylog.org/t/multiple-filter-in-query/16083 "2020-06-26T06:16:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sohailmeer](https://avatars.discourse-cdn.com/v4/letter/s/9fc348/32.png) [@sohailmeer](https://community.graylog.org/u/sohailmeer)\
**Post date:** [June 26, 2020, 6:16am UTC](https://community.graylog.org/t/multiple-filter-in-query/16083/1 "2020-06-26T06:16:19Z")

</div>

Hi,

I am using this product for 2 or 3 months from now and it is amazing few of the things are very smooth and going if you have good understanding with the logs nature. I’ve been searching for an option and trying to achieve a thing i don’t know if it is possible. I want to get the multi syntax result.

for example when we set an search filter in linux log file  
cat /var/log/messages |grep Jun\ 26 |grep -E “ERROR|FAILED|WAR” we get the result what we actually seeking for i am trying same thing for Graylog as well if hit the query like

source:“xyz” AND log\_file\_path:"/var/log/messages" AND message:“ERROR|FAILED|WARN”

This is just an example draw it wont work, i know to get the message we have to put AND between filters. So is there anyway we can put all the filters in one?

---

<div class="post-metadata">

**Author:** ![ttsandrew](https://avatars.discourse-cdn.com/v4/letter/t/97f17d/32.png) [@ttsandrew](https://community.graylog.org/u/ttsandrew)\
**Post date:** [June 30, 2020, 9:39pm UTC](https://community.graylog.org/t/multiple-filter-in-query/16083/2 "2020-06-30T21:39:55Z")

</div>

Hello @sohailmeer:

message: “ERROR|FAILED|WARN” is searching for that literal string in the body. Is that what you want? If not, then I think what you want is grouping.

source:“xyz” AND log\_file\_path:"/var/log/messages" AND (message:“ERROR” OR message:“FAILED” OR message:“WARN”)

[https://docs.graylog.org/en/3.3/pages/searching/query\_language.html](https://docs.graylog.org/en/3.3/pages/searching/query_language.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [July 14, 2020, 9:39pm UTC](https://community.graylog.org/t/multiple-filter-in-query/16083/3 "2020-07-14T21:39:57Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
