search command overview
search command to retrieve events from one or more index datasets, or to filter search results that are already in memory.
You can retrieve events from your datasets using keywords, quoted phrases, wildcards, and field-value expressions. When the
search command is not the first command in the pipeline, it is used to filter the results of the previous command.
The required syntax is in bold.
- search <search-expression>
rex command examples
search command syntax details
This documentation applies to the following versions of Splunk® Cloud Services: current