This documentation does not apply to the most recent version of Splunk.
Click
here for the latest version.
Download topic as PDF
How Splunk Web procedures have changed from version 5 to version 6
Use this topic to learn about some of the major differences in how to accomplish tasks using the Splunk Web user interface from version 5.x to version 6.x.
What's changed?
Procedure/Task
|
How you used to do it
|
How you do it now
|
First time login to Splunk Enterprise
|
In 5.x, the Splunk Enterprise launcher has two tabs: Welcome and Splunk Home. In Welcome, you can Add data and Launch search app.
|
In 6.x, Splunk Enterprise launches with Home. The main parts of Home include the Splunk Enterprise navigation bar, the Apps panel, the Explore Splunk Enterprise panel, and a custom default dashboard (not shown here).
|
Returning to Home
|
In 5.x, to return to Home/Welcome you selected the Home app from the App menu.
|
In 6.x, you click the Splunk logo in the upper left of the navigation bar. Doing so always returns you to Home.
|
Edit account information
|
In 5.x you accessed your account information (change full name, email address, default app, timezone, password) under Manager > Users and authentication > Your account.
|
In 6.x, you access account information directly from the Splunk navigation under Administrator > Edit Account.
|
Logout from Splunk Enterprise
|
In 5.x, you clicked the "Logout" button on the navigation bar.
|
In 6.x, you select Administrator > Logout. (If you are not logged in as Administrator, Splunk Enterprise displays the full name of the logged in user. Click this name to bring up the "Logout" menu option)
|
Manager/Settings
|
In 5.x, you edited all objects and system configurations from the Manager page or from the "Administrator" link on the navigation bar.
|
In 6.x, you access these configurations directly from the Settings menu. There is no separate Manager page.
|
Manage Apps: Edit permissions for installed apps, create a new app, or browse Splunk Apps for community apps
|
In 5.x, you used Manager -> Apps or selected from the App menu.
|
In 6.x, you use the Apps menu on the navigation bar or the gear icon beside the word Apps on the Home page.
|
Search
|
Summary, Search
Searches & Reports
Dashboards & Views
|
Search
Reports
Dashboards
|
Extract fields or show source
|
In the search results, click on the arrow to the left of the timestamp of an event and select Extract Fields or Show Source.
|
In the search results, click on the arrow to the left of the timestamp of an event and then click Event Actions. Select Extract Fields or Show Source.
|
Find the list of alerts
|
In the navigation bar, you selected "Alerts".
|
In the navigation bar, you select Activity > Triggered Alerts.
|
Find the timeline
|
In 5.x, the timeline was always visible as part of the dashboard after you ran a search. You can hide the timeline.
|
In 6.x, you can only view the timeline if you're looking at the Events tab after you run a search.
|
This documentation applies to the following versions of Splunk® Enterprise:
6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.5.0, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12
Feedback submitted, thanks!