Common commands

There are many commands in Splunk that you will likely use on a daily basis when searching data within Splunk. These common commands are outlined in the following table:

Command

Description

chart / timechart

This command output results in a tabular and/or time-based output for use by Splunk charts.

dedup

This command de-duplicates results based upon specified fields, keeping the most recent match.

eval

This command evaluates new or existing fields and values. There are many different functions available for eval.

fields

This command specifies the fields to keep or remove in search results.

head

This command keeps the first X (as specified) rows of results.

lookup

This command looks ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.