This is not current Splunk documentation.
Splunk 3.4.2 is the latest version. Only use this page with older Splunk 2.0.x.
Splunk 3.4.2 is the latest version. Only use this page with older Splunk 2.0.x.
Splunk User Manual (Splunk v2.0)
Faster Splunking Tricks
Ready, Fire! Aim.
The biggest speed boost you can give yourself is to splunk first and ask questions later. Start with a broad search for the first term that comes to mind. Then use Ctrl-Alt-click (on Macs, cmd-option-click) to filter out results you don't want. Use the same approach you do when Googling or when piping a file through longer and longer grep commands to filter it down to what you're looking for.
No comments have been submitted.