Book Image

Implementing Splunk (Update)

Book Image

Implementing Splunk (Update)

Overview of this book

Table of Contents (20 chapters)
Implementing Splunk Second Edition
Credits
About the Authors
About the Reviewers
www.PacktPub.com
Preface
Index

Clicking to modify your search


Though you can probably figure it out by just clicking around, it is worth discussing the behavior of the GUI when moving your mouse around and clicking.

  • Clicking on any word or field value will give you the option to Add to search or Exclude from search (the existing search) or (create a) New search:

  • Clicking on a word or a field value that is already in the query will give you the option to remove it (from the existing query) or, as above, (create a) new (search):

Event segmentation

In previous versions of Splunk, event segmentation was configurable through a setting in the Options dialog. In version 6.2, the options dialog is not present – although segmentation (discussed later in this chapter under field widgets section) is still an important concept, it is not accessible through the web interface/options dialog in this version.

Field widgets

Clicking on values in the Select Fields dialog (the field picker), or in the field value widgets underneath an event,...