Splunk Stream search syntax
The table summarizes Stream source
and sourcetype
search syntax.
Stream 6.1.0 or later | Example | |
Syntax | source=stream:<stream-id> sourcetype=stream:<protocol> | |
Search for a specific <stream-id> | source=stream:<stream-id> | source=stream:http, source=stream:tcp |
Search for all <protocol> streams | sourcetype=stream:<protocol> | sourcetype=stream:http, sourcetype=stream:tcp |
Note: The name that Stream assigns to an individual <stream-id> is the same as the underlying protocol.
Stream data capture configuration basics | Supported protocols |
This documentation applies to the following versions of Splunk Stream™: 7.1.0, 7.1.1
Feedback submitted, thanks!