<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk query vs Splunk search in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-query-vs-Splunk-search/m-p/762616#M13002</link>
    <description>&lt;P&gt;I suppose the confusion comes from the fact that "query" is the standard term used with SQL while the thing you do in Splunk with SPL is normally called a "search". Some people simply use the term "query" when talking about searches (especially if they have RDB background).&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jul 2026 10:12:18 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2026-07-30T10:12:18Z</dc:date>
    <item>
      <title>Splunk query vs Splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-query-vs-Splunk-search/m-p/762610#M13000</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I just want to understand what is the exact difference between query and search.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 08:22:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-query-vs-Splunk-search/m-p/762610#M13000</guid>
      <dc:creator>_Raj</dc:creator>
      <dc:date>2026-07-30T08:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query vs Splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-query-vs-Splunk-search/m-p/762611#M13001</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249545"&gt;@_Raj&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The term is typically used interchangeably to describe the "SPL" - Splunk Processing Language that is run to produce results. The SPL can be referred to as the query or search, although some users may refer to the SPL as the query and the 'search' being the action/execution of said query.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In terms of Splunk knowledge objects, for example, a 'saved search' is a definition containing a query and other meta/params which when executed returns the results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;STRONG&gt;Did this answer help you? If so, please consider&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 08:39:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-query-vs-Splunk-search/m-p/762611#M13001</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-07-30T08:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk query vs Splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-query-vs-Splunk-search/m-p/762616#M13002</link>
      <description>&lt;P&gt;I suppose the confusion comes from the fact that "query" is the standard term used with SQL while the thing you do in Splunk with SPL is normally called a "search". Some people simply use the term "query" when talking about searches (especially if they have RDB background).&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 10:12:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-query-vs-Splunk-search/m-p/762616#M13002</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-07-30T10:12:18Z</dc:date>
    </item>
  </channel>
</rss>

