Skip to content

Michael Simko

Splunk Search Command Of The Week: dedup

Using the dedup Command

What is the Splunk dedup Command? The Splunk dedup command, short for “deduplication”, is an SPL command that eliminates duplicate values in fields, thereby reducing

Splunk Search Command Of The Week: spath

Using the spath Command

Your dilemma: You have XML or JSON data indexed in Splunk as standard event-type data. Sure, you’d prefer to have brought it in as an

conceptual illustration of different license sizes

Estimating Splunk License Sizes

What is a Splunk License? A Splunk license is a file that houses information about your license entitlement. This tells you what your abilities and