Splunk® Enterprise

Search Reference

Download manual as PDF

Splunk version 4.x reached its End of Life on October 1, 2013. Please see the migration information.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Welcome to the Search Reference manual

In this manual, you'll find a reference guide for the Splunk user who is looking for a catalog of the search commands with complete syntax, descriptions, and examples for usage.

If you're looking for an introduction to searching in Splunk, check out the User Manual's topics about search to get you started.

See the "List of search commands" in the Search Overview chapter for a catalog of the search commands, with a short description of what they do and related search commands. Each search command links you to its reference page in the Search Command chapter of this manual. If you want to just jump right in and start searching, the Search command cheat sheet is a quick reference complete with descriptions and examples.

Before you continue, read "How to use this manual" for the conventions and rules used in this manual.

Make a PDF

If you'd like a PDF version of this manual, click the red Download the Search Reference as PDF link below the table of contents on the left side of this page. A PDF version of the manual is generated on the fly for you, and you can save it or print it out to read later.

Understanding SPL syntax

This documentation applies to the following versions of Splunk® Enterprise: 4.3, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.3.6, 4.3.7


Gfrazier: i recommend you go through this tutorial: <br />http://www.splunk.com/base/Documentation/latest/User/WelcometotheSplunktutorial<br />it will teach you how to use the search interface.

March 21, 2011

I add search some index information and I like to exclude my id or my team's id from the search. How do I do this

March 21, 2011

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters