Skip to content

Splunk Snippets



makeresults can be used to run SPL queries without having to specify an index or lookup. This can be very helpful when testing out search logic or specifying simple data in a dashboard panel.

| makeresults
| eval hello = "world"
| table hello



Likeness Algorithms

More details can be found on my Splunk String Likeness post.

| makeresults
| eval domain1 = ""
| eval domain2 = ""
| eval domain3 = ""
| jellyfisher jaro_winkler(domain1,domain2)
| rename jaro_winkler AS jaro_winkler_1_and_2
| jellyfisher jaro_winkler(domain1,domain3)
| rename jaro_winkler AS jaro_winkler_1_and_3