LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

How is a Splunk SPL search built, and what does sourcetype="access_combined" error | top 10 uri do?

A search is a chain of commands joined by pipes |: each command takes the result table of the previous one and transforms it. This example fetches web-access events containing "error" and returns the 10 most frequent URIs among them.

SPL pipeline: index, implicit search narrows to 12,480 error events, top 10 uri reduces to a 10-row table

* Each pipe hands a smaller, reshaped table to the next command. *

search-args | cmd1 cmd-args | cmd2 cmd-args | ...

Every search starts with an implicit search command that retrieves events from the index. It understands:

  • keywords: error
  • Boolean expressions: (error OR failure) NOT success, with AND implicit between terms
  • phrases: "database error"
  • wildcards: fail* matches fails, failure …
  • field values and comparisons: code=404, code!=404, code>200
  • field presence: code=* or NOT code=*

Think of the result as a table: each event is a row, each field a column. Every command after a pipe changes that table: filters rows, adds computed columns, aggregates rows into statistics. Reading an SPL query left to right is reading a data pipeline.

Tip: the pipe works like the Unix shell pipe; if you can read cat log | grep error | sort | uniq -c, you can read SPL.

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026