Splunk Search

How to enable the Search Assistant in 6.5.0?

dlpco
Path Finder

I am using 6.5.0 of Splunk with the Free license install. When in the Search and Reporting screen, I get no Search Assistant. I would like to have that available but can't figure out how to get it turned on.

Suggestions???

Tags (2)
0 Karma

ftan_splunk
Splunk Employee
Splunk Employee

it's a bug and will be fixed in 6.5.1
after 6.5.1, splunk assistant under free license will use Compact mode by default and the mode can't be changed

lakromani
Builder

This has been asked for before,

https://answers.splunk.com/answers/454966/search-syntax-highlighting-free-license-650.html

With this response:
Engineering has confirmed that this is a bug, it should be fixed in a forthcoming maintenance release.

inventsekar
SplunkTrust
SplunkTrust

Please follow these steps
1. On the Splunk bar, select [User_account_name] > Account Settings.
2. Under the Search section, look for Search assistant and select Compact, Full, or None. Click Save.
3. The None mode turns the search assistant off.

https://docs.splunk.com/Documentation/Splunk/6.5.0/Search/Usingthesearchassistant

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

lakromani
Builder

I down voted this answer because user asked for how to do it in free license mode. It's not possible this way.

dlpco
Path Finder

In the free license, there is no such entry in the Splunk bar to be able to do that. Is there some way to turn it on again with the free license?

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...