search assistant

noun

An online quick reference guide for Splunk search language and syntax that is accessed via the search bar. When the search assistant is active it displays typeahead information as you type terms into the bar. When you type a search command into the bar, the search assistant gives you directions for how to use the command, usage examples, examples of recent searches you've built that use the command, common next commands, and so on. The search assistant also offers a "help" link to the search command documentation if you need it.

You can open and close the search assistant by clicking the green down-arror beneath the search bar in Splunk Web.

For more information

In the User Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time