Searching and Reporting
The Searching and Reporting app lets you search your data, create data models and pivots, save your searches and pivots as reports, configure alerts, and create dashboards.
The Search Manual discusses how to search and use the Search Processing Language (SPL). See the Search Reference for a catalog of the search commands with syntax, descriptions, and examples for each command.
|You are new to Splunk Enterprise and want to learn how to search and use the search processing language||Start with the Search Tutorial|
|Learn more about the search processing language||Get started with Search|
|Find a specific search command or function||Command quick reference|
|Manage search jobs||About jobs and jobs management|
|You are new to Splunk Enterprise and want to learn about data model and pivot||Pivot Tutorial|
|Learn about data models and how to build them||About data models|
|Learn more about Pivot and how to use the Pivot Editor to design tables and charts.||Pivot Manual|
See more about reports and report management in the Reporting Manual.
|Use search commands to generate reports||About transforming commands and searches|
|Learn about the different kinds of visualizations (tables, charts, event listings, and so on)||Dashboards and Visualizations|
|Save a search or pivot as a report||Create and edit reports|
|Accelerate a report
Understand requirements for report acceleration
|Schedule a report||Schedule reports|
|Generate a PDF of your report||Generate PDFs of your reports and dashboards|
See how to create and dispatch alerts in the Alerting Manual.
|Learn about alerts||About alerts|
|Set up email notifications, RSS notifications, or alert scripts||Set up alert actions|
|See alerting examples||Alert Examples|
|See recently triggered alerts||Review triggered alerts using the Alert Manager|
|Set up alerts using the configuration files||Configure alerts in savedsearches.conf|
Creating dashboards and visualizations
|Learn about dashboards||Overview of dashboards|
|Learn how to create and edit dashboards||Create and edit dashboards via Splunk Web|
|Learn about the different kinds of visualizations (tables, charts, event listings, and so on)||Visualization Reference|
|Learn about the default activity and summary dashboards||Splunk default dashboards|
|Learn about the Splunk Web Framework||Splunk Web Framework Overview|
Splunk Enterprise administration
This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11