Splunk Search

Are there any good lispy docs out there?

Lowell
Super Champion

Has anyone come across any good references or resource material explaining lispy? This is visible from the search inspector and can give you some good insights into how Splunk is executing your core search, but I've not been able to find any docs, videos, or blogs that actually explain it.

So far, the best references I have are answers on this site:

0 Karma

dchassaing_splu
Splunk Employee
Splunk Employee

This .conf talk that @martin_mueller gave in 2016 and 2017 is a good lispy resource; it includes demos in the Job Inspector as well as some theory behind best search practices. In fact he also wrote the second Answers link you shared!

2016 Talk
Recording: http://conf.splunk.com/files/2016/recordings/fields-indexed-tokens-and-you.mp4
Slides: http://conf.splunk.com/files/2016/slides/fields-indexed-tokens-and-you.pdf

2017 Talk
Recording: https://conf.splunk.com/files/2017/recordings/fields-indexed-tokens-and-you.mp4
Slides: http://conf.splunk.com/files/2017/slides/fields-indexed-tokens-and-you.pdf

JLeeatCBA
Explorer
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...