Online Safety Community

What Are The Search Commands In Splunk?

The Splunk Commands are one of the programming commands which makes your search processing simple with the subset of language by the Splunk Enterprise commands. These commands are used to transform the values of the specified cell into numeric values. The following are the listed Splunk Search commands that are sorted according to the various categories.


These are one of the commands which can be used for the purpose of building the correlation searches
Append: It is described as one of the Appends which shows the sub-search results to present results.
Appendcols: This command shows all the fields of sub-search results to the present results like first to first and last to last soon.
Appendpipe: This command is completely used to generate the results in sub-search, which is applied to the current result that set to the previous one.
Rules: This command will easily find all the association rules in between the field values.
Associate: This command is used to identify the correlations in between fields.
Contingency, Constable, stable: This command helps to build a contingency table for a particular two fields.
Correlate: This is the top correlation command which can easily calculate the relation between the different fields.
Diff: This command shows the complete outputs in between two search results.
Join: This command will help to combines all the results from main pipeline results through sub-search.
Lookup: It can be used to explicit all invokes in the field value lookups.
Self-join: This command shows the join results with itself without depending on other commands.
Set: It is used to perform the multiple sets of operation like intersect, union and diff especially on the sub-searches.
Stats: This command is used to complete all the statistics that are grouped optionally by the fields.
Transaction: By using this command all the groups of the search results into the group of transactions.

Data and indexes

Data and Indexes are one of the categories in the Splunk search commands which are used to learn all the data that can be added, deleted or manage the data from the resources that are placed in the summary indexes.

View and manage Data:

All the view and manage data commands will help to return the relevant information regarding the data that contains in your indexes. The data present in the indexes cannot be modified easily. The following are some of the commands which are used to delete and add the specific data from your indexes.

Audit: This data command will helpful to throwback all the basic information that can be stored in the local audit index.
Data model: This command is used to provide all the relevant information regarding the data model object or data model.
Dbinspect: It is used to return all the specific information particularly about the specific index.
Event count: This command is used to connect with the number of events in the index.
Metadata: This command is used to return all the sources list, types of sources as well as the hosts in the specified index.
Typeahead: This command is helpful to return all the typeahead information in the specified prefix.
Delete: This command is used to delete all the specific events or search results to delete from the index.
Input: This delete in Splunk search commands will help to add or disable sources in the indexes

Managing the summary indexes:

These commands in the Splunk search commands are helpful to create and manage all the summary indexes.
Collect, stash: This command is used to provide all the search results into a summary index.
Overlap: It is used to find all the events in the summary index that you have missed.
Sichart: This command is used to calculate the summary index of the chart.
Sirare: It can be helpful to conclude the summary indexing version of rare.
Stats: This command will be helpful to summarize the stats version.

Modify fields and field values:

This type of commands will help to modify all the fields and the value.
Convert: It helps to convert all the numerical values in the field.
Filldown: This command is used to replace all the null values with the last non-null values.
Fillnull: It is used to change all the null values with a particular value.
Makemv: If you want to change the specified field in the index then uses this command while researching.
Nomv: This command is used to change the particular multivalve field to single value field during the search.
Rename: This is helpful to rename the specified value by using the wildcards in the specific multiple fields.

Geographic and location:

This Splunk geographical command is used to search all the results
Geom: This command is used to add the field to every event that contains geographic structures in the map visually. But this command requires the external loops to get installed.
Geomfilter: This command will accept the specific bounding box in the maps which point the respective filtered out.
Geostats: It helps to generate all the statistics that are clustered into geographical bins which particularly rendered on the whole world map.?


The metrics in Splunk search commands will completely work with all the metrics data without any hassle.
Mcollect: This command is used to translate all the events in the form of metric data points and can be successfully inserted into the data points of the search head.
Even collect: It is used to convert the stats of events into metric points by inserting them into the metric index.
Mstats: It helps to calculate all the visualization of the date through metric names dimension fields in the respective indexes.

Prediction and trending:

The prediction and trending commands of Splunk are helping to detect all the values that create great visualizations.
Predict: This command is used to enable all algorithm series that predict the values of fields.
Trendline: It is used to calculate and compute all the averages in the fields
X11: This command completely enables the trend with respect to your data by deleting all the seasonal patterns.


Time is one of the categories in the Splunk search commands which is used to search on the basis of time ranges which can add more information to your programs.
Gentimes: This command is used to return all the respective results by matching the time range.
Localize: It is used to return all the list of the time ranges among the time ranges along with the search results.
Reltime:  This command is used to differentiate the difference between the human-readable times to the which adds more value to the fields in the search results.

Views: 54


You need to be a member of Online Safety Community to add comments!

Join Online Safety Community

Take our poll!

Take our poll!

Latest Activity

Training Doyens posted an event

Live Webinar on How to Hire, Retain, and Grow a Diverse & Inclusive Workforce at 26468 E Walker Dr, Aurora, Colorado 80016

February 19, 2019 from 1pm to 2pm
OVERVIEWSTOP - Do not put out another hiring notice until you fully consider the ramifications of diversity and inclusion in the workplace.  Why is this important? First, if you have diverse customers, those customers will relate to the diverse employees helping them or selling to them. Second, to avoid a homogeneous culture where people want to fit in so desperately that…See More
1 hour ago
swethakumar posted a blog post

Fire Safety Tips For the WorkPlace

Fires are a preventable catastrophe which will cause many thousands of greenbacks harm, loss of production, loss of jobs and loss of lives.When controlled properly, the hearth is one in all our greatest allies within the geographic point, a quite helpful partner of trade. once it’s uncontrolled but, it will become our worst and most feared enemy.There are several easy things that you simply as an employee will do to minimize the danger of fireplace within the geographic point. Here are some…See More
20 hours ago
Profile IconJames Pollard, Steve Carter, Steven Eaton and 5 more joined Online Safety Community
Training Doyens posted events


Important of Warning sign 1 Reply

Warning sign is a type of traffic sign that guide a hazard ahead on the road. Having proper warning sign on the road provide a healthy environment.Continue

Tags: Signs, Workplace, Safety, Sign, Warning

Started by healthandsafetysigns. Last reply by Jen McDade on Monday.

Workers paticipation in safety management 2 Replies

Workers paticipation in safety management is the aspect which is required to be implemented in the OHSAS 18001 2007 version. , I invite our experience community members to share their views on the…Continue

Tags: management, safety, in, paticipation, Workers

Started by SafetyRaja. Last reply by Tara safe Dec 27, 2018.

How to improve safety culture of factories 4 Replies

How to improve safety culture of factories having mostly contract and casual ever changing workers for whom training and monitoring both are major issues. Such qorkers are mainly meeting accidents in…Continue

Started by Harkant Dave. Last reply by Jen McDade Dec 24, 2018.

[General Industry] What is your workplace's policy on headphones? Working on one currently. 1 Reply

I have been tasked to create a headphones (and cell phone) policy for my employer. I am relatively new to this company, but so far they've let everyone listen to headphones and mess around with their…Continue

Tags: general, industry, distraction, music, phone

Started by Kyle C. Johnson. Last reply by Jen McDade Dec 19, 2018.

Biggest Challenge? 5 Replies

As a distributor of safety supplies, as a webmaster who is trying to sell safety supplies online, one of my main goals is to try to provide value above and beyond just selling supplies and product.So…Continue

Started by Safetyguy08. Last reply by Jen McDade Dec 18, 2018.



© 2019   Created by Safety Community.   Powered by

Badges  |  Report an Issue  |  Terms of Service