Welcome to the Search Manual
This manual discusses Splunk Search and how to use the Splunk search processing language.
If you are new to Splunk Enterprise and search, start with the "Search Tutorial". The Search Tutorial introduces you to the Search and Reporting app and takes you through adding data, searching your data, and building simple reports and dashboards.
Before you can start using Splunk search,
- Add data to your Splunk instance. See how to get data into Splunk in the "Getting Data In Manual".
- Understand how indexing works in Splunk Enterprise. See how Splunk processes data in the "Managing Indexers Manual".
- Understand fields and knowledge objects, such as host, source type, and event type. See the "Knowledge Manager Manual".
For the catalog of search commands and arguments that make up the Splunk search processing language, see the Search Reference Manual.
What's in Splunk Search
This documentation applies to the following versions of Splunk® Enterprise: 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.1.14