Searching in Splunk

Searches in Splunk usually start with a base search, followed by several commands that are delimited by one or more pipe (|) characters. The result of a command or search to the left of the pipe is used as the input for the next command to the right of the pipe. Multiple pipes are often found in a Splunk search to refine data results continually as needed. As we go through this chapter, this concept will become very familiar to you. The following screenshot illustrates the search bar in Splunk:

Splunk allows you to search for anything that might be found in your log data. For example, the most basic search in Splunk might ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.