Searching in Splunk
It would be negligent for a book on mastering Splunk searching to not mention the dashboard of version 6.0.
The search dashboard
If you take a look at the Splunk search dashboard (and you should), you can break it down into four general areas. They are given as follows:
- The search bar: The search bar is a long textbox into which you can enter your searches when you use Splunk Web.
- Range picker: Using the (time) range picker, you can set the period over which to apply your search. You are provided with a good supply of preset time ranges that you can select from, but you can also enter a custom time range.
- How-To (panel): This is a Splunk panel that contains links that you can use to access the Search Tutorial and Search Manual pages.
- What-To (panel): This is another Splunk panel that displays a summary of the data that is installed on the current Splunk instance.
The new search dashboard
After you run a new search, you're taken to the New Search page. The search bar and...