Splunk Search

best way to run a query

howard_mclean
New Member

what is the best approach to run splunk queries

Tags (1)
0 Karma

deepakc
Builder

Start here - it shows the basics   
https://www.splunk.com/en_us/blog/customers/splunk-clara-fication-search-best-practices.html 

Here are all the many different commands with SPL with examples  - once you have developed the basic concepts, you can start to apply various commands for your use cases. 

https://docs.splunk.com/Documentation/SplunkCloud/9.1.2312/SearchReference/ListOfSearchCommands

 

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...