Search Tutorial


About the Search Tutorial

About the Search Tutorial

Splunk Search is the primary interface for using Splunk Enterprise to run searches, save reports, and create dashboards. This Search Tutorial is written for the user who is new to Splunk Enterprise and the Splunk Search feature.

What's in this tutorial?

This manual guides the first user through adding data, searching the data, saving the searches as reports, and creating dashboards. If you're new to Splunk Search, this is the place to start.

Make a PDF

For a PDF version of this manual, click the red Download the Search Tutorial as PDF link below the table of contents on the left side of this page.

Note: Do not copy and paste searches directly from the PDF document into Splunk Web. In some cases, doing so causes errors because of hidden characters that are included in the PDF formatting.

This documentation applies to the following versions of Splunk: 6.0 , 6.0.1 , 6.0.2 , 6.0.3 , 6.0.4 , 6.0.5 , 6.0.6 , 6.0.7 , 6.0.8 , 6.0.9 , 6.0.10 , 6.1 , 6.1.1 , 6.1.2 , 6.1.3 , 6.1.4 , 6.1.5 , 6.1.6 , 6.1.7 , 6.1.8 , 6.1.9 , 6.2.0 , 6.2.1 , 6.2.2 , 6.2.3 , 6.2.4 , 6.2.5 View the Article History for its revisions.

You must be logged into in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!