<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: btool cheat sheet in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/515151#M87246</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/32102"&gt;@youngsuh&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;happy splunking!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by me and the other contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Aug 2020 09:26:44 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-08-20T09:26:44Z</dc:date>
    <item>
      <title>btool cheat sheet</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/514983#M87234</link>
      <description>&lt;P&gt;Does anyone have a cheat sheet for btool to help newbies?&lt;/P&gt;&lt;P&gt;Here is my version of btool cheat sheet:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool &amp;lt;conf_file_prefix&amp;gt; &amp;lt;sub-cmd&amp;gt; &amp;lt;context&amp;gt; --debug "%search string%"
splunk show config &amp;lt;config file name&amp;gt; | grep -v "system\/default"

Step 1.
splunk btool inputs list --debug "%search string%"  &amp;gt;&amp;gt; /tmp/splunk_inputs.txt
Step 2.
Import into excel using space as a separator.
Step 3.  Use excel to filter feature to look for the settings&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Explanation:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;conf_file_prefix&amp;gt;: props, inputs, outputs, transforms&lt;/P&gt;&lt;P&gt;&amp;lt;sub-cmd&amp;gt;:&amp;nbsp; list, display, user, dir&lt;/P&gt;&lt;P&gt;&amp;lt;context&amp;gt;:&amp;nbsp;--app=search&lt;/P&gt;&lt;P&gt;"%serch string%": input the search you're looking for&lt;/P&gt;&lt;P&gt;I'd prefer piping the command to "less" command.&lt;/P&gt;&lt;P&gt;Splunk documents:&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/CommandlinetoolsforusewithSupport#btool" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/CommandlinetoolsforusewithSupport#btool&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/Usebtooltotroubleshootconfigurations" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/Usebtooltotroubleshootconfigurati...&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/CommandlinetoolsforusewithSupport" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/CommandlinetoolsforusewithSupport&lt;/A&gt;&lt;/P&gt;&lt;P&gt;External Site:&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkonbigdata.com/2018/10/03/splunk-btool/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://splunkonbigdata.com/2018/10/03/splunk-btool/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks, everyone who replied.&amp;nbsp; I'd consolidated the information into the top page.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 01:39:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/514983#M87234</guid>
      <dc:creator>youngsuh</dc:creator>
      <dc:date>2020-08-20T01:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: btool cheat sheet</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/514987#M87235</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/32102"&gt;@youngsuh&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I didn't find a page as you would and it's a strange thing because Splunk documentation is usually very complete and structured.&lt;/P&gt;&lt;P&gt;Anyway, in these pages, you can find all the infos you need:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/Usebtooltotroubleshootconfigurations" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/Usebtooltotroubleshootconfigurations&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/CommandlinetoolsforusewithSupport" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Troubleshooting/CommandlinetoolsforusewithSupport&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkonbigdata.com/2018/10/03/splunk-btool/" target="_blank"&gt;https://splunkonbigdata.com/2018/10/03/splunk-btool/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 15:42:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/514987#M87235</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-08-19T15:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: btool cheat sheet</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/514992#M87236</link>
      <description>&lt;P&gt;Try&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool help&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;I prefer to pipe btool output to&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;grep -v "system\/default"&lt;/LI-CODE&gt;&lt;P&gt;to eliminate noise from the default settings.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 15:53:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/514992#M87236</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-19T15:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: btool cheat sheet</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/515000#M87237</link>
      <description>&lt;P&gt;And remember that what you got from btool is what is on disk. If/when you want to see what is running config you must use&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="java"&gt;splunk show config &amp;lt;config file name&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 16:06:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/515000#M87237</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-19T16:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: btool cheat sheet</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/515151#M87246</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/32102"&gt;@youngsuh&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;happy splunking!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by me and the other contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 09:26:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/515151#M87246</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-08-20T09:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: btool cheat sheet</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/574985#M101618</link>
      <description>&lt;P&gt;&lt;A href="https://splunkonbigdata.com/splunk-btool/" target="_blank"&gt;https://splunkonbigdata.com/splunk-btool/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the new link for btool in Splunkonbigdata.com&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 04:36:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/574985#M101618</guid>
      <dc:creator>Abhay</dc:creator>
      <dc:date>2021-11-16T04:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: btool cheat sheet</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/705969#M116771</link>
      <description>&lt;P&gt;I use the good old grep command when I needed a list of indexes referenced in all inputs on all folders ; like this:&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;splunk btool inputs list --debug | grep index
&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 00:04:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/705969#M116771</guid>
      <dc:creator>yulsplunkops</dc:creator>
      <dc:date>2024-12-05T00:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: btool cheat sheet</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/749737#M119101</link>
      <description>&lt;P&gt;that is my 99% use case for btool , the aggregated list of xxxxx.conf by file --debug then filter with grep.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 13:43:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/749737#M119101</guid>
      <dc:creator>mwk1000</dc:creator>
      <dc:date>2025-07-14T13:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: btool cheat sheet</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/749738#M119102</link>
      <description>&lt;P&gt;If you know stanza name you should add also it.&amp;nbsp;&lt;BR /&gt;Currently there is also splunk app called Admin's little helper, which you could use to run btool from MC or splunk cloud. I strongly recommended to install and use it in any distributed environments!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://splunkbase.splunk.com/app/6368" target="_blank"&gt;https://splunkbase.splunk.com/app/6368&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 13:53:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/btool-cheat-sheet/m-p/749738#M119102</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-07-14T13:53:30Z</dc:date>
    </item>
  </channel>
</rss>

