Splunk Enterprise version 8.2 will no longer be supported as of September 30, 2023. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. Click here for the latest version.Download topic as PDF
The following are the spec and example files for
# Version 8.2.5 # # This file effects how the search assistant (typeahead) shows the syntax for # search commands.
* The name of the syntax type you are configuring. * Follow this field name with one syntax= definition. * Syntax type can only contain a-z, and -, but cannot begin with - syntax = <string> * The syntax for your syntax type. * Should correspond to a regular expression describing the term. * Can also be a <field> or other similar value.
Last modified on 04 February, 2022
This documentation applies to the following versions of Splunk® Enterprise: 8.2.5
Feedback submitted, thanks!