Splunk Search

Advice on how to better search Splunk>answers

rfazio
Explorer

I'm trying to work on a dashboard that's gotta be nothing new. But when I search in Splunk>answers I'm not able to drive any value from my searches. I really don't want to be asking the same question as documented before but the search appears to "OR" all search words.

So when I try to find help relating to "passing a value into a drilldown link". I put into my search window "drilldown link value".

I would expect to get the intersection of the keywords "drilldown, link value". But I get 13,746 results of which most do NOT include all three words.

However, if I search each individually I get the following results
drilldown - 811
link - 3722
value - 10738

All three total 15,271 ... which given a modest overlap, I suspect the result of 13,746 is a union rather than an intersection.

I don't see an advanced search button. Are their any tricks in the syntax? Quoting does not seem to help and generates a different kind of funkiness (technical term).

TIA,
faz

0 Karma
1 Solution

ChrisG
Splunk Employee
Splunk Employee

Maybe try using Google to do a site search? site:answers.splunk.com drilldown link value

https://www.google.com/#q=site:answers.splunk.com+drilldown+link+value

View solution in original post

MuS
Legend

Hi rfazio,

I can only talk for myself, but I usually use google to search splunk docs or answers like this:

https://www.google.ch/search?q=answers.splunk.com+dashboard+drilldown

to get back result about dashboards drill downs.

But I'm sure @piebob is open for enhancement requests 😉

cheers, MuS

piebob
Splunk Employee
Splunk Employee

we're definitely aware of the search issues on Answers, and also recommend using google to search. i'm considering various options, and appreciate your patience!

0 Karma

Michael_Wilde
Splunk Employee
Splunk Employee

Perhaps the answers search box should just run a google search query and not use whatever search engine comes with this platform. Even searching for exact phrases like "lookup default.meta" yields results, but that text isn't in the results.

0 Karma

TaylorWhitt
Explorer

I find this extremely ironic given what splunk is used for.... searching.

0 Karma

rfazio
Explorer

Like a black fly in your chardonnay ...

0 Karma

rfazio
Explorer

It's all good. Google works great!

Believe me that should not be Splunk's priority... I see a few other things in line ahead of this 🙂

Thanks!
faz

ChrisG
Splunk Employee
Splunk Employee

Maybe try using Google to do a site search? site:answers.splunk.com drilldown link value

https://www.google.com/#q=site:answers.splunk.com+drilldown+link+value

rfazio
Explorer

I would have expected Native American rain dance prior to using Google to search the site. That works very well

I'm not saying an FAQ will help as the "FAQ" button is way off in the corner...but it would not hurt.

Perhaps a simple button next to the search window "advanced search" that sends the search request to Google for use?

Just saying.

Thanks all for the quick response.
faz

btw.... why the drama with special characters. I could not search on "splunk>answers" as the greater than sign is changed to &gt.

0 Karma

ppablo
Retired

Hi @rfazio

Thanks for sharing all the details with your experience searching Answers and suggestions. I've shared this post with the right folks to hopefully get some improvements done sooner than later.

Patrick

0 Karma

MuS
Legend

HeHe, I was typing for too long 😉

ppablo
Retired

Yes, even as the content manager for the site, I use Google to return better results than using the built-in search on Splunk Answers as @ChrisG and @MuS have suggested. For the time being, this is the best approach unfortunately. We're fully aware of this issue and are currently looking into improving this.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...