Download topic as PDF
This documentation does not apply to the most recent version of Splunk.
for the latest version.
How Splunk Web procedures have changed from version 5 to version 6
Use this topic to learn about some of the major differences in how to accomplish tasks using the Splunk Web user interface from version 5.x to version 6.x.
||How you used to do it
||How you do it now
|First time login to Splunk Enterprise
||In 5.x, the Splunk Enterprise launcher has two tabs: Welcome and Splunk Home. In Welcome, you can Add data and Launch search app.
||In 6.x, Splunk Enterprise launches with Home. The main parts of Home include the Splunk Enterprise navigation bar, the Apps panel, the Explore Splunk Enterprise panel, and a custom default dashboard (not shown here).
|Returning to Home
||In 5.x, to return to Home/Welcome you selected the Home app from the App menu.
|In 6.x, you click the Splunk logo in the upper left of the navigation bar. Doing so always returns you to Home.
|Edit account information
||In 5.x you accessed your account information (change full name, email address, default app, timezone, password) under Manager > Users and authentication > Your account.
|In 6.x, you access account information directly from the Splunk navigation under Administrator > Edit Account.
|Logout from Splunk Enterprise
||In 5.x, you clicked the "Logout" button on the navigation bar.
|In 6.x, you select Administrator > Logout. (If you are not logged in as Administrator, Splunk Enterprise displays the full name of the logged in user. Click this name to bring up the "Logout" menu option)
||In 5.x, you edited all objects and system configurations from the Manager page or from the "Administrator" link on the navigation bar.
|In 6.x, you access these configurations directly from the Settings menu. There is no separate Manager page.
|Manage Apps: Edit permissions for installed apps, create a new app, or browse Splunk Apps for community apps
||In 5.x, you used Manager -> Apps or selected from the App menu.
|In 6.x, you use the Apps menu on the navigation bar or the gear icon beside the word Apps on the Home page.
Searches & Reports
Dashboards & Views
|Extract fields or show source
||In the search results, click on the arrow to the left of the timestamp of an event and select Extract Fields or Show Source.
|In the search results, click on the arrow to the left of the timestamp of an event and then click Event Actions. Select Extract Fields or Show Source.
|Find the list of alerts
||In the navigation bar, you selected "Alerts".
|In the navigation bar, you select Activity > Triggered Alerts.
|Find the timeline
||In 5.x, the timeline was always visible as part of the dashboard after you ran a search. You can hide the timeline.
|In 6.x, you can only view the timeline if you're looking at the Events tab after you run a search.
Last modified on 18 August, 2017
This documentation applies to the following versions of Splunk® Enterprise:
6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.5.0, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12