Navigating Splunk Web

This topic discusses navigating the different views in Splunk Web, the Splunk web browser interface.

About Splunk Home

The Splunk Home page is your interactive portal to the data and apps in your Splunk deployment. The first time you log into your Splunk deployment, you land on the Splunk Home page. All of the apps that you have access to appear on this page.

You can personalize the home page with in-product bookmarks for quick access to guides, manuals, apps, knowledge objects, and so on.

Administrators can:

  • Share bookmarks with all users in one operation.
  • Control the domains in which bookmarks can be created.

Users can:

  • Access your search history for various apps in a single view, without having to navigate to each app to see the history associated with that app.
  • Filter the Knowledge Object list by App and Owner for quicker access to those objects.

There are minor differences between the Splunk Home page for Splunk Enterprise and Splunk Cloud Platform.

The following image shows the Home page for a user with administrator access on Splunk Enterprise:

This image shows the Splunk Home page for Splunk Enterprise. The Apps panel extends the full length of the left side of the window. The Splunk bar is at the top of the window. There is a set of quick link tabs above the center panel. The first tab is for bookmarks. The other tabs contain quick links for common tasks.
Note: Your Splunk account might be configured to start in another view instead of Splunk Home, such as Search or Pivot in the Search & Reporting app.

Apps panel

The Apps panel lists the apps which are installed on your Splunk instance and that you have permission to use. Select an app from the list to open it.

By default the Search & Reporting app, which is often referred to as the Search app, is pinned to the top of the list. For apps that you use frequently, you can pin the apps to move them to the top of the list.

About the Splunk bar

Use the Splunk bar to navigate Splunk Web. You can use the Splunk bar to to switch between apps or perform tasks such as get the health of your Splunk platform deployment, monitor the activity of your search jobs and alerts, add data, manage settings and edit your Splunk configuration, view system-level messages, get help using Splunk software, and set your profile preferences.

The following image shows the Splunk bar in the Search app in Splunk Enterprise. The Splunk bar in Splunk Cloud Platform has the same elements and menus.

This image shows the Splunk bar in the Search app in Splunk Enterprise. From left to right, the first item on the Splunk bar is the Splunk logo. The second item to the right of the bar is the icon for Health of Splunk Deployment. Then, the menu icons for the Find search box, Activity, Settings, Notifications, Help, User Profile, and Apps, which are described in the following sections.

Health of Splunk Deployment menu

Use the Health of Splunk Deployment menu in the upper-right corner of the Splunk bar to monitor the operational health of your Splunk platform deployment and its underlying subsystems. The health indicator uses a traffic-light status to show the overall health of the deployment.

  • Green indicates that monitored features are operating normally.
  • Yellow indicates a warning or non-critical degradation.
  • Red indicates a severe issue that can affect functionality.
  • Gray indicates that health reporting is turned off or snoozed.

The health indicator is available only to users whose roles include the list_health capability. See Define roles on the Splunk platform with capabilities.

Screenshot of the Health of Splunk Deployment window on the Splunk bar. In the upper-right corner, a red exclamation point inside a red-outlined square indicates the current deployment health status. The window lists health statuses for monitored features and explains the green, yellow, red, and gray status indicators.

Activity menu

The Activity menu provides shortcuts to the Jobs and Triggered alerts views.

  • Click Jobs to open the search jobs manager window, where you can view and manage currently running searches.
  • Click Triggered Alerts to view scheduled alerts that are triggered.

Settings menu

The Settings menu lists the configuration pages for knowledge objects, distributed environment settings, system and licensing, data, and authentication settings. If you do not see some of these options, you do not have the permissions to view or edit those options.

The following image shows the Settings menu in Splunk Enterprise:

This image shows the Settings menu on the Splunk bar for a Splunk Administrator in Splunk Cloud Platform. The Settings menu contains options to manage Knowledge objects, Data, System settings, Distributed Environment settings, and User access.

The Settings menu in Splunk Enterprise contains the same options, however there are several additional large icons to the left of the menu to access the Explore Data and Monitoring Console pages.

Notifications menu

All system-level error messages are listed on the Notifications menu. When you have a new message to review, a numerical notification appears next to the Notifications menu. The notification indicates the number of messages that you have. The following screenshot shows the Notifications window, which indicates that there are two messages relating to file integrity checks and a security risk warning.

This image shows the Notifications menu on the Splunk bar. To the right side of the Notifications menu is a green circle containing the number two.

Help and Support

For assistance with the Splunk platform, such as accessing product documentation, the Customer Portal, or the Splunk community, or contacting support or providing feedback, select the question mark icon in the upper-right corner of the Splunk bar. You can also use the Help menu to learn more about your Splunk platform instance and view information about what’s new in the current release.

Screenshot of the Help menu opened from the question mark icon on the Splunk bar, showing links to documentation, customer and community support, contact and feedback options, instance information, and what’s new.

User Profile menu

Use the User Profile menu to edit your account settings, change preferences, or to log out of the Splunk platform instance.

  • If you installed the Splunk platform, for example to step through the Search Tutorial, the user menu displays "Administrator" because that is the default user name for a new installation.
  • If you are not a Splunk administrator, the name on the user menu is your Splunk user name.

This image shows the User Profile menu which displays the settings for Profile, Preferences, and Log out.

Through the Profile menu, you can change account settings such as name and email address, and set a new password for the account.

Through the Preferences menu, you can:

  • Set a time zone that is different than the default system time zone.
  • Set a default application other than Splunk Home.
  • Restart background search jobs when the Splunk software is restarted.
  • Change the background to a dark theme. The default is a light theme.

Apps

The Apps launcher icon for the Apps menu appears in the upper-right area of the navigation bar next to the User Profile menu and is used to launch apps. Use this menu to quickly switch between the Splunk platform applications that you have installed on your Splunk instance, such as the Search & Reporting app. You can also use the search field in the Apps menu to find apps.

The following screenshot shows the Apps window, which includes the Manage setting that takes you to a page where you can view and manage all of your Splunk platform apps.

Screenshot of the Apps menu opened from the waffle app launcher icon on the Splunk bar, showing a list of installed apps and a gear icon at the top right called Manage that links to the Apps page.

Return to Splunk Home

Select the Splunk logo on the Splunk bar to return to Splunk Home from any other view in Splunk Web.