Summary

In this chapter, we provided the reader with an exploration of some of the Splunk advanced search topics, such as some simple (search commands) optimization strategies based on the search command objectives. In addition, we took a look at search operators, tagging, transactional searches, subsearches, and macros. We used working examples in some cases, leveraging some of the most-used Splunk search commands (chart, eval, timechart, top, transaction, and where).

In the next chapter, we will review advanced tables, charts, and field topics and provide practical examples.

Get Mastering Splunk now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.