Basic Search: SPLUNK
Meta-Data:The Meta-data is generally the first command of the search. As a best practice, we should include 4 fields always in the first line of the query. This is not mandatory but adding them is always better from Splunk search perspective. 1. INDEX: the repository of Splunk where your data resides. 2. HOST : this … Read more