Module 5-6
Module 5-6
Module 5-6
Basic
Search
B
A
C
B
search mode
timeline
paginator
Fields
sidebar
timestamp
selected fields events
custom
time
ranges
Splunk Fundamentals 1
12 01/07/2024 | 24 May 2018
Time Range Abbreviations
• Time ranges are specified in the Advanced tab of the time range
picker
• Time unit abbreviations include:
s = seconds m = minutes h = hours d = days w = week mon = months y = year
Note
If time specified, it must be in
MM/DD/YYYY:HH:MM:SS format.
Timeline legend
shows the
scale of the
timeline
Splunk Fundamentals 1
15 01/07/2024 | 24 May 2018
Viewing a Subset of the Results with Timeline
• To select a narrower time
range, click and drag
across a series of bars
– This action filters the
current search results
Does not re-
execute the search
– This filters the events
and displays them in
reverse chronological
order (most recent
first)
area_code=404
action=purchase status=503
sourcetype=access_combined
Note
For more information, please see:
http://docs.splunk.com/Documentation/Splunk/latest/Data/Listofpretrainedsourcetypes
fields 1
– Click
1 a field in the
Fields sidebar
2– Click Yes in the upper right
action = * is added
to the search criteria
Click a value to add the field/value pair to your search – in this case,
action = addtocart is added to the search criteria
These two searches return results This one does not return results
• Example: s t a t u s ! = 200
– Returns events where s t a t u s field exists and value in field doesn’t
equal 200
Note
The results from a search using != are a
subset of the results from a similar
search using NOT.