Splunk® Enterprise

Search Reference

Download manual as PDF

Splunk version 4.x reached its End of Life on October 1, 2013. Please see the migration information.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Search command cheatsheet

Cheatsheet PDF

The Search command cheatsheet is a quick command reference complete with descriptions and examples. The cheat sheet is an eight-page PDF file. You can open the PDF and save the file on your computer.

Open the Search command cheatsheet


Note: The examples in this cheatsheet use a leading ellipsis (...) to indicate that there is a search before the pipe operator. A leading pipe indicates that the search command is a generating command and prevents the command-line interface and Splunk Web from prepending the search command to your search.


Answers

Have questions about search commands? Check out Splunk Answers to see what questions and answers other Splunk users had about the search language.

PREVIOUS
Search commands by category
  NEXT
Splunk SPL for SQL users

This documentation applies to the following versions of Splunk® Enterprise: 4.3, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.3.6, 4.3.7


Comments

We are working on updates to them! But, we don't generally update these documents for the latest versions (5.0.x) between major releases (5.0). Thanks!

Sophy, Splunker
August 27, 2013

Are "Search Command Cheat Sheet" & "Search Language Command Reference" PDFs updated for latest version of Splunk?

Miteshvohra
August 25, 2013

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters