Release Notes

 


Search language and knowledge extensions

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Search language and knowledge extensions

Dynamic field lookups

In this feature, users can create lookup tables that can be updated and used by searches (for example, mapping a list of ip addresses to mac addresses). Lookup lists can be static (stored in a csv file), dynamically generated from a search, or retrieved from an external database. Lookups typically add or replace fields in search results. Functionality for this feature includes:

Learn more about adding dynamic information to your searches in the Knowledge Manager Manual.

Relative time modifiers

In addition to Splunk's standard built-in time ranges relative to search time (last day, last week, last month etc.), Splunk now allows users to specify more flexible time ranges. These additional time periods include those that are:

Administrators can configure these relative time ranges for individual apps via a configuration file.

Learn more about using relative time modifiers in the User Manual.

Improved and new search commands

This feature includes new search commands, as well as enhancements to existing search commands:

Learn more about new and improved search commands in the Search Reference Manual.

Improvements to field renaming, tagging, and aliasing

This feature includes several improvements to Splunk's handling of fields and sourcetypes:

Learn more about aliasing fields in the Knowledge Manager Manual.

Learn more about tagging fields in the User Manual.

Advanced anonymization

In previous versions of Splunk, masking confidential data within events required administrators to write custom transforms. Splunk now supports the same syntax as 'sed', a Unix utility which reads a file and modifies the input as specified by a list of commands. Capabilities include:

Benefits

For users:

This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!