Search interface and language enhancements
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Search interface and language enhancements
This feature includes various improvements to Splunk's search interface and language including:
- Ability to click on on an event timestamp to drill down into a time period
- Ability to double click on the timeline to zoom in on events
- Ability to sort columns in tables
- Ability to create relative time modifers via Splunk Web
- Ability to filter by status on the Jobs page
- Ability to use new UTC time manipulation functions to the
evalcommand - Ability to use weeks and quarters in relative time spans
- New
concurrencycommand that makes it easier to compute concurrency when you have events that have a field that represents duration - New
tablecommand creates a custom table using only specified fields - New
rtordercommand buffers events from real-time search to emit them in ascending time order when possible - New option to
timechartcommand to drop partial buckets - New option to
topandrarecommands to insert a row for 'all other values'
This documentation applies to the following versions of Splunk: 4.1 , 4.1.1 , 4.1.2 , 4.1.3 , 4.1.4 , 4.1.5 , 4.1.6 , 4.1.7 , 4.1.8 View the Article History for its revisions.