Splunk Tech Talks
Deep-dives for technical practitioners.

Search Basics in Splunk!

Splunk Employee
Splunk Employee

View our Tech Talk: Platform Edition, Search Basics in Splunk

Search Basics is one of the most important learning topics for new users getting started with Splunk. Splunk’s powerful search capabilities allow you to search and investigate your data, regardless of its structure, to find the needle in your data haystack. You can easily explore your data further by visualizing relationships within your data to quickly spot outliers, adding visualizations and reports to create custom dashboards, and creating ad hoc alerts when you identify new issues or threats. 

Tune in to learn:

    • The power of Splunk Search, as we like to call “Schema on the Fly”
    • A beginner’s level introduction to Search, SPL, and Pivots
    • What you can do with your search results using reports, alerts, dashboards, and visualizations!

Tech Talks conversations will remain open for two weeks after the live talk. Then you can continue the conversation within Splunk Answer with the tag Search.

Splunk Employee
Splunk Employee

Here is the Q&A from the live session. Enjoy!

Q:  Why use only Splunk? Why can’t I go for something that is open source?

A:  Ultimately the question of open vs closed source depends on how much of the implementation your company is willing to take on yourselves. Splunk provides a more turnkey solution than some of the open source solutions out there, so it's a cost vs benefit decision.

Q: Why was index and sourcetype was not used to search?

A: Index and sourcetype would further refine the results if there were multiples of each, but in this demo there was only the demo data so they weren't required.

Q: If wanna to compare this result with last month result , could you do it, to be able to calculate the revenue percentage

A: Absolutely. You would need to evaluate fields for the current and previous months separately. You could use a sub search for the previous month and set the earliest and latest filters as -1m to avoid hard coding the date ranges.

Q: Is there an available resource available to better learn Splunk's Search Processing Language (SPL)?

A: Hi, there are two things. First the documentation https://docs.splunk.com/Documentation/Splunk/8.0.6/Search/GetstartedwithSearch and second the search reference https://docs.splunk.com/Documentation/Splunk/8.0.6/SearchReference/WhatsInThisManual .
There is also the fundamentals course that is free.  https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html

Q: Is there a cheat sheet for using SPL?

A: There is this quick guide - https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf which has a few common SPL commands.