Splunk® Enterprise

Search Tutorial

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

About Splunk Home

Splunk Home is your interactive portal to the apps and data accessible from this Splunk instance. The main parts of Home include a search bar and three panels: Apps, Data, and Help.

6.1 splunk home.png


Finding Splunk Home

If this is a new installation, Splunk Home is the first page that you see when you log into Splunk for the first time. Otherwise, your account might be configured to start in another view such as Search or Pivot in the Search & Reporting app.

You can return to Splunk Home from any other view by clicking the Splunk logo at the top left in Splunk Web.


App search bar

The app search bar is a shortcut that lets you run a search in a specified app context, without clicking through to the app. It is similar to the standard Splunk search bar and includes a time range picker. It also includes an App menu that lets you select the app context in which to run your search.


Apps and workspaces

In the Apps panel, you will see workspaces for the apps that are installed on your Splunk server that you have permission to view. The workspace displays a menu of the views and objects in the app context. Select the App to open it or select a content page listed in the workspace to go directly to that view.

For an out-of-the-box Splunk Enterprise installation, you see one App in the workspace. When you have more than one app, you can drag and drop the apps within the workspace to rearrange them.

Discover new apps or manage existing apps by clicking the buttons at the bottom of the panel:

  • Find more apps to install on Splunk.
  • Manage apps already installed on Splunk.

Data panel

The Data panel is a shortcut to add new data and manage your data inputs. When you have data in Splunk, you can see a brief summary of it in the Data panel.

Tutorial home datapanel.png


The Data panel displays statistical data about events indexed by the local Splunk Enterprise instance. It shows how long ago data was indexed earliest and latest and the volume of data you have in this instance.

Help panel

The Help panel provides links to pages that help you learn how to use Splunk Enterprise, including video tutorials, the Splunk Answers forums, the Splunk Support portal, and Splunk Enterprise online documentation.

Next steps

Continue to the next topic to learn how to navigate your Splunk instance.

PREVIOUS
Start Splunk Enterprise and launch Splunk Web
  NEXT
Navigating Splunk Web

This documentation applies to the following versions of Splunk® Enterprise: 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters