Admin Manual

 


How Splunk Works

Live Tail

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Live Tail

Live Tail for Splunk Web works just like tail -f (in Linux/Unix). Search for any text in data as it is indexed into Splunk. Live Tail streams data to the browser based on a simple text search.


Live Tail has a variety of uses. Some of the more common use cases are:


Use Live Tail in Splunk Web

Live Tail launches in a new window (or new tab - depending on your browser configuration). The Live Tail processor takes the search terms you input (before they get piped to data processing commands), creates a search based on those, and streams search results to your browser.


To start Live Tail, select View in Live Tail menu item in the search bar drop-down menu.


The Live Tail interface

Overview of controls in the Live Tail window:


Start Live Tail from the Splunk CLI

  1. Log into Splunk. ./splunk login
  1. Use the live-tail CLI command to start Live Tail.
  1. Type: ./splunk live-tail "your search string", where "your search string" is whatever simple search terms you want to search for (surrounded by quotes).

Current limitations

The following are the current limitations of Live Tail:


This documentation applies to the following versions of Splunk: 3.2 , 3.2.1 , 3.2.2 , 3.2.3 , 3.2.4 , 3.2.5 , 3.2.6 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.