Common commands

There are many commands in Splunk that you will likely use on a daily basis when searching data within Splunk. These common commands are outlined in the following table:



chart / timechart

This command output results in a tabular and/or time-based output for use by Splunk charts.


This command de-duplicates results based upon specified fields, keeping the most recent match.


This command evaluates new or existing fields and values. There are many different functions available for eval.


This command specifies the fields to keep or remove in search results.


This command keeps the first X (as specified) rows of results.


This command looks ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.