Knowledge Management

What are some good Splunk tips & tricks you know?

SplunkIsLife
Explorer

I write a monthly tips & tricks blog for Splunk users/consumers at my company but have steadily been running out of ideas. Anyone have anything they think is worth calling out? It can be as simple as a niche command, the idea of macros, alternatives to joins, really anything, fire away! The more the merrier. Thanks!

Tags (1)
0 Karma

SplunkIsLife
Explorer

eventstats, chart, appends, dashboards, _time manipulation, account settings, how to comment, permissions, cron, transforming commands, lookups, logTypes, regex, html panels, transpose, alternatives to joins, interesting fields, splunk toolbar, app enhancements.

I like the drilldowns idea! I don't use tstats much, i'll look into it. advanced use of lookups is | lookup or [ |inputlookup]?, don't use transaction super frequently but can look at that too. keep the ideas coming!

0 Karma

dflodstrom
Builder

What are some things you've already covered? Tstats is important, when to use stats instead of a transaction, "advanced" use of lookups, visualization tips like customizing drilldowns via the UI in later versions.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...