Splunk Quick Reference
Splunk Quick Reference
pkgadd -d ./splunk_product_name.pkg
pkgadd -n -d ./splunk_product_name.pkg
System configurations
From the System configurations area, you can manage:
System settings: Manage system settings including ports, host name, index path, email server
settings (for alerts), and system logging.
Server controls: Restart Splunk.
License: View license usage statistics and apply a new license.
Data inputs: Add data to Splunk from scripts, files, directories, and network ports.
Forwarding and receiving: Configure this Splunk instance to send or receive data.
Indexes: Create new indexes and manage index size preferences.
Access controls: Specify authentication method (Splunk or LDAP), create or modify users, and
manage roles.
Distributed search: Set up distributed search across multiple Splunk instances.
Deployment: Deploy and manage configuration settings across multiple Splunk instances.
User options: Manage user settings, including passwords and email addresses.
Apps and knowledge
From the Apps and knowledge area, you can manage:
Apps: Edit permissions for installed apps, create new apps, or browse Splunkbase for apps
created by the community.
Searches and reports: View, edit, and set permissions on searches and reports. Set up alerts
and summary indexing.
Event types: View, edit, and set permissions on event types.
Tags: Manage tags on field values.
Fields: View, edit, and set permissions on field extractions. Define event workflow actions and
field aliases. Rename sourcetypes.
Lookups: Configure lookup tables and lookups.
User interface: Create and edit views, dashboards, and navigation menus.
Advanced search: Create and edit search macros. Set permissions on search commands.
All configurations: See all configurations across all apps.