Navigating Splunk Web
About Splunk Home
The Splunk Home page is your interactive portal to the data and apps in your Splunk deployment. The first time you log into your Splunk deployment, you land on the Splunk Home page. All of the apps that you have access to appear on this page.
You can personalize the home page with in-product bookmarks for quick access to guides, manuals, apps, knowledge objects, and so on.
Administrators can:
- Share bookmarks with all users in one operation.
- Control the domains in which bookmarks can be created.
Users can:
- Access your search history for various apps in a single view, without having to navigate to each app to see the history associated with that app.
- Filter the Knowledge Object list by App and Owner for quicker access to those objects.
There are minor differences between the Splunk Home page for Splunk Enterprise and Splunk Cloud Platform.
The following image shows the Home page for a user with administrator access on Splunk Enterprise:
Apps panel
The Apps panel lists the apps which are installed on your Splunk instance and that you have permission to use. Select an app from the list to open it.
By default the Search & Reporting app, which is often referred to as the Search app, is pinned to the top of the list. For apps that you use frequently, you can pin the apps to move them to the top of the list.
Center panel and quick link tabs
The center panel contains a set of quick link tabs. The first tab is Bookmarks, where you can set your own bookmarks and see the bookmarks shared with you. The other tabs provide quick access to other information.
Quick link tabs
Splunk Home has a set of tabs that you can use to gain access to information. The following table describes these tabs:
| Tab | Description |
|---|---|
| Bookmarks | Use this tab to access your own bookmarks, bookmarks your organization has defined, and Splunk recommended bookmarks. |
| Dashboard | Use this tab to access your favorite dashboard faster. You can add a dashboard created either using Simple XML or created through Dashboard Studio as your home dashboard. |
| Search history | This tab shows the list of searches that you've run recently. You can set how far back to keep the search history. The maximum is the last 90 days. |
| Recently viewed | This tab shows the list of knowledge objects that you accessed in the last 30 days, including alerts, dashboards, datasets, and reports. |
| Created by you | This tab shows all of the knowledge objects that you have created, organized by knowledge object type. |
| Shared with you | This tab shows all the knowledge objects that you have access to, organized by knowledge object type. |
About the Splunk bar
Use the Splunk bar to navigate Splunk Web. You can use the Splunk bar to to switch between apps or perform tasks such as get the health of your Splunk platform deployment, monitor the activity of your search jobs and alerts, add data, manage settings and edit your Splunk configuration, view system-level messages, get help using Splunk software, and set your profile preferences.
The following image shows the Splunk bar in the Search app in Splunk Enterprise. The Splunk bar in Splunk Cloud Platform has the same elements and menus.
Find search box
To search for objects within your Splunk deployment, use the Find search box. The Find search box performs matches that are not case sensitive on the ID, labels, and descriptions in built-in and saved objects. For example, if you type error, it returns the knowledge objects and information in the Splunk Help Portal that contain that term, as shown in the following image.
The saved objects, where they exist, are organized into the following categories: Reports, Dashboards, Datasets, and Data models.
You can also run a search for the word error in your event and metric data. From the list displayed in the Find search box, select Open error in search to run a search in the Search & Reporting app using the word you specified in the Find search box.
Help and Support
For assistance with the Splunk platform, such as accessing product documentation, the Customer Portal, or the Splunk community, or contacting support or providing feedback, select the question mark icon in the upper-right corner of the Splunk bar. You can also use the Help menu to learn more about your Splunk platform instance and view information about what’s new in the current release.
Apps
The Apps launcher icon for the Apps menu appears in the upper-right area of the navigation bar next to the User Profile menu and is used to launch apps. Use this menu to quickly switch between the Splunk platform applications that you have installed on your Splunk instance, such as the Search & Reporting app. You can also use the search field in the Apps menu to find apps.
The following screenshot shows the Apps window, which includes the Manage setting that takes you to a page where you can view and manage all of your Splunk platform apps.
Return to Splunk Home
Select the Splunk logo on the Splunk bar to return to Splunk Home from any other view in Splunk Web.