Splunk Search

Any intellisense enhancements / plug-ins?

mwagstaff
Explorer

Hi all - are there any intellisense plug-ins that enhance the existing Splunk search bar? A few examples of enhancements that I think would be really helpful:

  • If I start typing the name of a macro that isn't in my search history, it would be great to have it appear in the dropdown with syntax description, search details, etc.
  • Auto completion of field names would be cool, with perhaps the top 10 values appearing in the dropdown to give a preview of what data is contained within said field
  • Tag name auto completion
  • More detailed and expanded examples of usage and syntax for search keywords, with links to the appropriate help page on the Splunk site
0 Karma

MHibbin
Influencer

I think for the first three points of yours they would be enhancement requests.

However, for your last point, are you aware of the documentation on the search commands

http://docs.splunk.com/Documentation/Splunk/4.2.3/SearchReference/WhatsInThisManual

This should contain all you need, also when you do start to type the command in the search bar there will be a drop-down that appears and informs you of the usage and some examples, also there will be a link, "help", which links to the relevant page in the documentation above.

Regards,

Matt

Get Updates on the Splunk Community!

Harnessing Splunk’s Federated Search for Amazon S3

Managing your data effectively often means balancing performance, costs, and compliance. Splunk’s Federated ...

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...