Splunk® Enterprise

Search Tutorial

Download manual as PDF

Download topic as PDF

Additional resources

You can continue to use the tutorial data, run more searches, and create more dashboards.

The following sections provide additional information and links.

Splunk Community

The Splunk Community is amazing and full of very active members who are supportive of new users. You can search for solutions or ask questions on Splunk Answers, connect with helpful and fun Splunk enthusiasts through chat groups, or meet users in your local area at User Groups near you. The Community portal has everything you need to discover how to set yourself up for success with the Splunk Community.

Search resources

This tutorial was a brief introduction to navigating the search interface and using the search language. It walked you through running some basic searches and saving the results as a report and dashboard, but you can do much more with the Splunk software. For more details, see the following manuals:

  • Search Manual: Explains how to search and use the Splunk Search Processing Language (SPL™). Look here for more thorough examples of writing Splunk searches to calculate statistics, evaluate fields, and report on search results.
  • Search Reference: Provides a reference for users who are looking for a catalog of the search commands with complete syntax, descriptions, and examples for usage.

Splunk documentation

Splunk has a wide range of documentation, including tutorials, use cases, and manuals for administrators, developers, and users, as well as SDK and SPL command syntax documentation.

There are separate manuals for searches, dashboards and visualizations, reports, pivots, and alerts.

You will find all of the information on the Splunk Documentation site.

Quick References

Splunk Quick Reference Guide
Contains information about fundamental concepts, features, and components in Splunk software. The guide also includes explanations and examples of common search commands and functions.
Dashboards Quick Reference Guide
Provides an overview of the most common operations, definitions, and commands that you will use when you create dashboards and visualizations.

Splunk Enterprise system requirements

The Search Tutorial presents a snapshot of the Splunk Enterprise system requirements. For an explanation of the requirements, see System Requirements in the Installation Manual.

Accessing your data

To learn more about the types of data you can add and using apps to index data, see Get started with getting data in in the Getting data In manual.

Education

To learn more about Splunk features and how to use them, see the Splunk selection of Education videos and classes.

Send us feedback

At the bottom of every page of this tutorial, and all of the Splunk documentation, is a quick form that you can use to send us feedback.

This screen image shows the "Was this topic useful" form at the bottom of each topic in the Splunk documentation.

PREVIOUS
Add more panels to dashboards
 

This documentation applies to the following versions of Splunk® Enterprise: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters