There are many commands in Splunk that you will likely use on a daily basis when searching data within Splunk. These common commands are outlined in the following table:
Command |
Description |
chart / timechart |
This command output results in a tabular and/or time-based output for use by Splunk charts. |
dedup |
This command de-duplicates results based upon specified fields, keeping the most recent match. |
eval |
This command evaluates new or existing fields and values. There are many different functions available for eval. |
fields |
This command specifies the fields to keep or remove in search results. |
head |
This command keeps the first X (as specified) rows of results. |
lookup |
This command looks ... |