<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Query Grammar in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Grammar/m-p/425019#M173386</link>
    <description>&lt;P&gt;I have a system that receives data from other systems for auditing purposes. One of these systems uses Splunk and I have a need to parse the queries. I am hoping someone can point me to a grammar for the Splunk language (Antlr, BNF, etc.).&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jan 2019 18:22:20 GMT</pubDate>
    <dc:creator>inovexsean</dc:creator>
    <dc:date>2019-01-25T18:22:20Z</dc:date>
    <item>
      <title>Splunk Query Grammar</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Grammar/m-p/425019#M173386</link>
      <description>&lt;P&gt;I have a system that receives data from other systems for auditing purposes. One of these systems uses Splunk and I have a need to parse the queries. I am hoping someone can point me to a grammar for the Splunk language (Antlr, BNF, etc.).&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 18:22:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Grammar/m-p/425019#M173386</guid>
      <dc:creator>inovexsean</dc:creator>
      <dc:date>2019-01-25T18:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query Grammar</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Grammar/m-p/425020#M173387</link>
      <description>&lt;P&gt;Install splunk and go to the &lt;CODE&gt;/opt/splunk/etc/system/README/&lt;/CODE&gt; directory.  Poke around in there.  You will find all that you need.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 19:33:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Grammar/m-p/425020#M173387</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-25T19:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query Grammar</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Grammar/m-p/425021#M173388</link>
      <description>&lt;P&gt;I'll try, and I appreciate the info, but my terminal here (which is not my development box) is pretty locked-down.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 19:36:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Grammar/m-p/425021#M173388</guid>
      <dc:creator>inovexsean</dc:creator>
      <dc:date>2019-01-25T19:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query Grammar</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Grammar/m-p/425022#M173389</link>
      <description>&lt;P&gt;Here is the search BNF: &lt;A href="https://gist.github.com/ChrisYounger/e51f9c3aba0f1ed02e5caee7d4a6128b"&gt;https://gist.github.com/ChrisYounger/e51f9c3aba0f1ed02e5caee7d4a6128b&lt;/A&gt;&lt;BR /&gt;
Datatypes BNF: &lt;A href="https://gist.github.com/ChrisYounger/520bdb1a7c8b22f5210213f83a3ab2db"&gt;https://gist.github.com/ChrisYounger/520bdb1a7c8b22f5210213f83a3ab2db&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I generated these by running &lt;CODE&gt;/opt/splunk/bin/splunk btool searchbnf list&lt;/CODE&gt; on  a fairly default Splunk 7.2 instance.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jan 2019 09:16:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Grammar/m-p/425022#M173389</guid>
      <dc:creator>chrisyounger</dc:creator>
      <dc:date>2019-01-26T09:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query Grammar</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Grammar/m-p/425023#M173390</link>
      <description>&lt;P&gt;Thanks. This'll be a big help.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 13:45:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Grammar/m-p/425023#M173390</guid>
      <dc:creator>inovexsean</dc:creator>
      <dc:date>2019-01-28T13:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query Grammar</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Grammar/m-p/425024#M173391</link>
      <description>&lt;P&gt;Just install Splunk on your local machine and check it out.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 00:12:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query-Grammar/m-p/425024#M173391</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-02-12T00:12:06Z</dc:date>
    </item>
  </channel>
</rss>

