About search actions and modes
This topic explains search actions and search modes that you can use to control your search experience.
Control search job progress
After you launch a search, you can access and manage information about the search's job without leaving the Search page. Click Job and choose from the available options there.
- Edit the job settings. Select this option to open the Job Settings dialog box, where you can change the job's read permissions, extend the job's lifespan, and get a URL for the job that you can use to share the job with others or put a link to the job in your browser's bookmark bar.
- Send the job to the background. Select this option if the search job is slow and you want to run the job in the background while you work on other Splunk Enterprise activities (including running a new search job).
- Inspect the job. Opens a separate window and displays information and metrics for the search job using the Search Job Inspector.
- Delete the job. Use this option to delete a job that is running, is paused, or which has finalized. After you delete the job, you can save the search as a report.
See "Saving and sharing jobs in Splunk Web" in the Search Manual.
Change the search mode
The Search mode controls the search experience. You can set it to speed up searches by cutting down on the event data it returns (Fast mode), or you can set it to return as much event information as possible (Verbose mode). In Smart mode (the default setting) it toggles search behavior based on the type of search you're running.
See "Set search mode to adjust your search experience" in the Search manual.
Save the results
The Save as menu lists options for saving the results of a search as a Report, Dashboard Panel, Alert, and Event type.
Other search actions
Between the job progress controls and search mode selector you can Share, Export, and Print the results of a search.
- The Share options shares the search job. This option extends the job's lifetime to seven days and set the read permissions to Everyone.
- The Export option exports the results. Select this option to output to CSV, raw events, XML, or JSON and specify the number of results to export.
- The Print option sends the results to a printer that has been configured.
Use the Close button to cancel the search and return to Splunk Home.
Continue to the next topic for a discussion about the format of the search results.
About the time range picker
About the search results tabs
This documentation applies to the following versions of Splunk® Enterprise: 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.1.13, 6.1.14