Query multiple streams

The DNIF Query Language lets you query multiple streams separated by a comma.


The syntax for querying multiple streams is as follows:

stream = stream_name1,stream_name2, stream_name3


The keyword stream is a standard DQL keyword used to retrieve data

stream_name1, stream_name2, and stream_name3 are the names of the streams from which the data will be retrieved. These stream names are separated by commas. Let’s now look at a practical example


The above DQL query retrieves all fields for each event in the FIREWALL, AUTHENTICATION, and THREAT streams.

Querying multiple streams in DQL Block

Querying multiple streams in Search Block