Splunk® Enterprise

Installation Manual

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

How Splunk Web procedures have changed from version 5 to version 6

Use this topic to learn about some of the major differences in how to accomplish tasks using the Splunk Web user interface from version 5.x to version 6.x.

What's changed?

Procedure/Task How you used to do it How you do it now
First time login to Splunk Enterprise In 5.x, the Splunk Enterprise launcher has two tabs: Welcome and Splunk Home. In Welcome, you can Add data and Launch search app. First login splunk5.png In 6.x, Splunk Enterprise launches with Home. The main parts of Home include the Splunk Enterprise navigation bar, the Apps panel, the Explore Splunk Enterprise panel, and a custom default dashboard (not shown here).

6.2 splunk home.png

Returning to Home In 5.x, to return to Home/Welcome you selected the Home app from the App menu.

Home link splunk5.png

In 6.x, you click the Splunk logo in the upper left of the navigation bar. Doing so always returns you to Home.

Home logo.png

Edit account information In 5.x you accessed your account information (change full name, email address, default app, timezone, password) under Manager > Users and authentication > Your account.

Edit account info splunk5.png

In 6.x, you access account information directly from the Splunk navigation under Administrator > Edit Account.

Administrator menu.png

Logout from Splunk Enterprise In 5.x, you clicked the "Logout" button on the navigation bar.

Logout splunk5.png

In 6.x, you select Administrator > Logout. (If you are not logged in as Administrator, Splunk Enterprise displays the full name of the logged in user. Click this name to bring up the "Logout" menu option)

Administrator menu.png

Manager/Settings In 5.x, you edited all objects and system configurations from the Manager page or from the "Administrator" link on the navigation bar.

Manager settings splunk5.png

In 6.x, you access these configurations directly from the Settings menu. There is no separate Manager page.

6.2 home settings menu.png

Manage Apps: Edit permissions for installed apps, create a new app, or browse Splunk Apps for community apps In 5.x, you used Manager -> Apps or selected from the App menu.

Manage apps splunk5.png

In 6.x, you use the Apps menu on the navigation bar or the gear icon beside the word Apps on the Home page.

6x manage apps.png

Search Summary, Search

Searches & Reports

Dashboards & Views

Search etc splunk5.png




Search etc.png

Extract fields or show source In the search results, click on the arrow to the left of the timestamp of an event and select Extract Fields or Show Source.

Select extract fields.png

In the search results, click on the arrow to the left of the timestamp of an event and then click Event Actions. Select Extract Fields or Show Source.


Find the list of alerts In the navigation bar, you selected "Alerts".

Alerts splunk5.png

In the navigation bar, you select Activity > Triggered Alerts.

Triggered alerts.png

Find the timeline In 5.x, the timeline was always visible as part of the dashboard after you ran a search. You can hide the timeline.

Timeline splunk5.png

In 6.x, you can only view the timeline if you're looking at the Events tab after you run a search.

Event timeline.png

Last modified on 18 August, 2017
How to upgrade a distributed Splunk Enterprise environment
Changes for Splunk App developers

This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.5.0, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters