Splunk Enterprise Security

sourcetype autopopulate

trojan_81
Path Finder

All

Newbie question. When I go to do a splunk search and do not know the exact sourcetype name, shouldn't it auto populate as I'm typing it in?

For example, suppose the sourcetype I wish to query is named: WindowsEventLogs

On my search I type in: index=* sourcetype="win

but it never autocompletes. In my lab environment it completes but not in this production environment. Is this a setting somewhere within splunk?

0 Karma

rkyadav
Path Finder

you can enable search assistant mode that would allow you auto populate option:

https://docs.splunk.com/Documentation/Splunk/7.3.3/Search/Usingthesearchassistant

OR
You can go to /etc/apps/user-prefs/default/user-prefs.conf :
Check for search assistant, below i have compact mode

[general]
search_syntax_highlighting = 1
search_assistant = compact

0 Karma

rkyadav
Path Finder

you can enable search assistant mode that would allow you auto populate option:

https://docs.splunk.com/Documentation/Splunk/7.3.3/Search/Usingthesearchassistant

OR
You can go to /etc/apps/user-prefs/default/user-prefs.conf :
Check for search assistant, below i have compact mode

[general]
search_syntax_highlighting = 1
search_assistant = compact

0 Karma

rkyadav
Path Finder

@trojan_81
If you good with above , please accept the answers.
thanks

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...