Splunk Enterprise

walklex: what is it telling me?

charlesmeo
Explorer

Given this search:

| walklex index=web prefix=host

what is the value contained in 'source'?

source = web~22~F3E2588C-834C-4B2A-B12B-3845A69B5304

I thought this might be a bucket id but it doesn't seem to be. First bit is the index name--what's the rest of it?

walklex documentation doesn't explain what is actually returned by this command, or how to use it.

Charles

Labels (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @charlesmeo,

It is the bucket name, a string composed of <index>~<id>~<guId>, where the delimiters are tilde characters. 

index = index name

id = bucket local id number

guid = guid of the indexer that host that index

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

charlesmeo
Explorer

Thanks @scelikok answer accepted. Still leaves the larger issue--documentation in this area (walklex, lispy) is pretty sketchy or non-existent.

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @charlesmeo,

It is the bucket name, a string composed of <index>~<id>~<guId>, where the delimiters are tilde characters. 

index = index name

id = bucket local id number

guid = guid of the indexer that host that index

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...