Splunk Cloud Platform

Search Experience preview

This documentation does not apply to the most recent version of Splunk Cloud Platform. For documentation on the most recent version, go to the latest release.

Sample modules

To help you learn how to search your data using SPL2, Search Experience includes a set of sample modules:

Audience Module name Description
New users Sample Module: Getting started with SPL2 This module helps you learn to how to search event data using the Splunk Search Processing Language, version 2 (SPL2). You will learn some basic commands, how to filter your data, and group search results. You'll be introduced to some common functions, how to use a lookup dataset, and create a simple join.
Users familiar with SQL Sample Module: Getting started with SPL2 for SQL users This module shows SQL users some common SELECT statements using SPL2.

Installing the sample modules

You install the sample modules from the My Workspace page.

  1. Click Install the sample content.
  2. You can install individuals modules or all of the sample modules:
    • To install a specific sample module, click Install next to the module name.
    • To install all of the sample modules, click Install All.

The modules are added to your My Workspace page.

Opening a sample module

To open a sample module:

  1. From My Workspace, double-click on the module name.
  2. The sample module opens in Search. Use the embedded comments to learn how to use SPL2 to create search statements.

When you use the sample modules, you must set the Global Time Range to All time.

See also

Related information
Sample data
Search Experience overview
Get started searching
Search using SPL2
Last modified on 14 January, 2023
Search using SPL2   Create, save, and manage modules

This documentation applies to the following versions of Splunk Cloud Platform: search2preview


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters