This is not current Splunk documentation.
Splunk 3.4.2 is the latest version. Only use this page with older Splunk 2.0.x.
Splunk 3.4.2 is the latest version. Only use this page with older Splunk 2.0.x.
Splunk User Manual (Splunk v2.0)
Tutorial
Similar
Similar events are those whose event types have nearly identical structures. The examples below are two events that have different event types, but you can seethe obvious similarity between them.

Splunking for Similar events lets you find events that don't quite match the search terms you typed, but are what you're looking for. Or, you can exclude similar events to block not just one unwanted type of event, but anything near it in structure.
No comments have been submitted.