Splunk Enterprise version 7.3 is no longer supported as of October 22, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. Click here for the latest version.Download topic as PDF
The following are the spec and example files for
# Version 7.3.1 # # This file effects how the search assistant (typeahead) shows the syntax for # search commands
* The name of the syntax type you're configuring. * Follow this field name with one syntax= definition. * Syntax type can only contain a-z, and -, but cannot begin with - syntax = <string> * The syntax for you syntax type. * Should correspond to a regular expression describing the term. * Can also be a <field> or other similar value.
Last modified on 29 July, 2019
This documentation applies to the following versions of Splunk® Enterprise: 7.3.1
Feedback submitted, thanks!