Skip to content

Instantly share code, notes, and snippets.

@domanchi
domanchi / cheatsheet.md
Last active April 5, 2024 06:30
[splunk cheatsheet] Splunk snippets, because their syntax is so confusing. #splunk

Splunk Queries

I really don't like Splunk documentation. Why is it so hard to find out how to do a certain action? So this is a cheatsheet that I constructed to help me quickly gain knowledge that I need.

Analysis

Events over time

index="my_log"