Home‎ > ‎Splunk‎ > ‎

Basic Search Review


Basic Search: 

Keywords 

search for error password

Booleans

OR, AND, NOT

Phrases

"web error". Find web error not web OR error

Field Searches:

status=404, user=admin 

Wildcards

status=40*  matches 40, 404, 401, etc.  "*" does not match spaces!
"_" space, colen, etc.  

Comparisons

=,!=, <, <=, >=, >    

Time Range: 

  • s = seconds
  • m = minutes
  • h = hours
  • d = days
  • w =weeks
  • mon = months
  • y = year
  • @ = snap to last total hour
  • earliest=-h  look back one hour
  • earliest=-2d@d latest=@d  looks back from two days ago, up to the beginning of time.  




Comments