Splunk Enterprise Security

sourcetype autopopulate

trojan_81
Path Finder

All

Newbie question. When I go to do a splunk search and do not know the exact sourcetype name, shouldn't it auto populate as I'm typing it in?

For example, suppose the sourcetype I wish to query is named: WindowsEventLogs

On my search I type in: index=* sourcetype="win

but it never autocompletes. In my lab environment it completes but not in this production environment. Is this a setting somewhere within splunk?

0 Karma

rkyadav
Path Finder

you can enable search assistant mode that would allow you auto populate option:

https://docs.splunk.com/Documentation/Splunk/7.3.3/Search/Usingthesearchassistant

OR
You can go to /etc/apps/user-prefs/default/user-prefs.conf :
Check for search assistant, below i have compact mode

[general]
search_syntax_highlighting = 1
search_assistant = compact

0 Karma

rkyadav
Path Finder

you can enable search assistant mode that would allow you auto populate option:

https://docs.splunk.com/Documentation/Splunk/7.3.3/Search/Usingthesearchassistant

OR
You can go to /etc/apps/user-prefs/default/user-prefs.conf :
Check for search assistant, below i have compact mode

[general]
search_syntax_highlighting = 1
search_assistant = compact

0 Karma

rkyadav
Path Finder

@trojan_81
If you good with above , please accept the answers.
thanks

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...