Splunk Cloud

Search Reference

Download manual as PDF

Download topic as PDF



Given some integer labeling of events into groups, finds searches to generate these groups.


findkeywords labelfield=<field>

Required arguments

Syntax: labelfield=<field>
Description: A field name.


Use the findkeywords command after the cluster command, or a similar command that groups events. The findkeyword command takes a set of results with a field (labelfield) that supplies a partition of the results into a set of groups. The command derives a search to generate each of these groups. This search can be saved as an event type.


Return logs for specific log_level values and group the results

Return all logs where the log_level is DEBUG, WARN, ERROR, FATAL and group the results by cluster count.

index=_internal source=*splunkd.log* log_level!=info | cluster showcount=t | findkeywords labelfield=cluster_count

The result is a statistics table:

Findkeywords ex1.png

The values of groupID are the values of cluster_count returned from the cluster command.

See also

cluster, findtypes


Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has about using the findkeywords command.


This documentation applies to the following versions of Splunk Cloud: 7.0.0, 6.5.0, 6.5.1, 6.5.1612, 6.6.0, 6.6.1, 6.6.3

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters