Splunk Cloud Platform

Search Experience preview

This documentation does not apply to the most recent version of Splunk Cloud Platform. For documentation on the most recent version, go to the latest release.

Release Notes for Search Experience preview

This page contains information about new features or enhancements made to the Search Experience preview, grouped by release version and the generally available release date.

March 2023

Version: Current, released on 22 March 2023

New Feature or Enhancement Description
Field extractions Extract new fields using a point-and-click interface. Select from a library of regular expressions or type in your own expression. Preview to validate that the correct data is extracted into fields. See Extract fields in a search.
Time extraction and time format conversion As part of extracting fields, you can extract timestamp-related fields and change the format of the time. Select from a library of regular expressions or type in your own expression for the time format conversion.
Sample modules enhanced The sample modules in Search were restructured and improved. There are now two sample modules for getting started with SPL2.
  • Getting started with SPL2: An introduction to using SPL2 to create searches, filter events, and summarize data.
  • Continue learning SPL2: Learn to extend searches, use functions, and search multiple datasets.
Performance and reliability improvements Using the Search Experience preview is faster and more reliable due to improvements in API calls response time and error rates.

January 2023

Version: Current, released on 24 January 2023

New Feature or Enhancement Description
Dashboards deprecated The dashboards feature has been deprecated. Feedback on creating dashboard during the preview has been valuable to the Splunk development teams. Investigations continue on how to merge the SPL2 capabilities directly into Dashboard Studio.


Existing dashboards in the Search Experience preview must be converted to modules. Refer to the email sent Dec 13, 2022 to preview participants for more information about the deprecation of the dashboard feature and how to convert dashboards into modules.

Home page removed To better integrate with existing and future Splunk Cloud products, the Home page has been removed. The new landing page is My workspace. The links on the Home page have been moved either to the App bar or to other pages in the UI.
Add descriptions to workspaces and modules If you have owner or editor access, you can add descriptions to workspaces and modules.
Add and remove export statements quickly You can add and remove export statements through the Options menu This image shows an icon with three dots in a vertical column. on the Outline panel, instead of manually typing the SPL2 export statement into the SPL Builder. Export statements are added immediately after the search statement that the export applies to.


Export statements are required to share search statements, as view datasets, in other modules. See Publishing searches.

Disable auto-run An auto-run option has been added to modules. This option automatically runs a search when an action, such as a command, is added to or deleted from a search. Auto-run is enabled by default. Disable this option to make multiple changes to your search statements before the search is run again.
Duplicate fields quickly You can use the Options menu This image shows an icon with three dots in a vertical column. to duplicate a field in your search results.
Ability to copy field values You can copy field values from the search results either by using the Options menu This image shows an icon with three dots in a vertical column. or copying directly from a field.
Link to keyboard shortcut documentation added to Help menu To more easily find the list of keyboard shortcuts you can use in the UI, a link to the documentation has been added to the Help menu This image shows a question mark inside a circle..
Last modified on 20 April, 2023
Troubleshoot search issues   Fixed issues

This documentation applies to the following versions of Splunk Cloud Platform: search2preview


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters