This is not current Splunk documentation.
Splunk 3.4.2 is the latest version. Only use this page with older Splunk 2.0.x.

Splunk User Manual (Splunk v2.0)

Splunk Search Interface

Tabbed Results

The results page also includes tabs for each of the built-in meta data values. The tab labels display how many results each tabbed panel has for the current search.

Click on a tab to bring it to the front. You will see a plot of the individual results for that value, plus helpful links on some tabs such as a Similar link for event types.

Tabbed results. Here the Event Types tab displays 17 event types for the current search. Note the Similar link at right.

If you see fewer Event Types, Tags, Source Types, Hosts or Sources than you know are in your Splunk index, try adding a maxresults:: value to your search greater than the default value of 10,000, e.g. maxresults::200000. The tabbed results only display those event types, hosts, etc. found in the first N results, where N is the value of maxresults.

Comments

No comments have been submitted.

close

Flash required to play this video.

Click here to download the free Flash Player.

Description:

Permalink: