How is a Splunk SPL search built, and what does sourcetype="access_combined" error | top 10 uri do?
A search is a chain of commands joined by pipes |: each command takes the result table of the previous one and transforms it. This example fetches web-access events containing "error" and returns the 10 most frequent URIs among them.
* Each pipe hands a smaller, reshaped table to the next command. *
search-args | cmd1 cmd-args | cmd2 cmd-args | ...
Every search starts with an implicit search command that retrieves events from the index. It understands:
- keywords:
error - Boolean expressions:
(error OR failure) NOT success, with AND implicit between terms - phrases:
"database error" - wildcards:
fail*matches fails, failure … - field values and comparisons:
code=404,code!=404,code>200 - field presence:
code=*orNOT code=*
Think of the result as a table: each event is a row, each field a column. Every command after a pipe changes that table: filters rows, adds computed columns, aggregates rows into statistics. Reading an SPL query left to right is reading a data pipeline.
Tip: the pipe works like the Unix shell pipe; if you can read cat log | grep error | sort | uniq -c, you can read SPL.