Splunk Search

Need a help in writing a query in splunk

jagan_vannala
Observer

I need a help for writing a query to fetch logs in the system

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jagan_vannala ,

as also @marnall  said, your question is too vague: which kind of logs are you speaking of?

did you already ingested or do you have to index them?

i you already indexed them, you must know index and sourcetype of them.

If you have to index them, see at https://docs.splunk.com/Documentation/SplunkCloud/8.1.10/Data/Getstartedwithgettingdatain the ways to ingest and to index logs.

Ciao.

Giuseppe

0 Karma

marnall
Motivator

What kind of logs are you trying to fetch? Does the system have a forwarder or Splunk Enterprise installed on it?

0 Karma

jagan_vannala
Observer

System having a splunk forwarder

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...