Skip to content
This repository was archived by the owner on Sep 2, 2025. It is now read-only.

Commit 05278fe

Browse files
author
Tracey Carter
committed
replacing screenshots for enhancements
1 parent 5e4044f commit 05278fe

File tree

3 files changed

+5
-1
lines changed

3 files changed

+5
-1
lines changed
526 KB
Loading

_images/logs/lo-openinsplunk.png

86.2 KB
Loading

_includes/logs/query-logs.rst

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,9 @@
11
1. Navigate to :guilabel:`Log Observer`. In the content control bar, enter a time range in the time picker if you know it.
22

3+
.. image:: /_images/logs/LogObserverEnhancements.png
4+
:width: 100%
5+
:alt: The Open in Splunk platform icon is at the top, right-hand side of the Logs table.
6+
37
2. Select :guilabel:`Index` next to :guilabel:`Saved Queries`, then select the indexes you want to query. If you want to search your Splunk platform (Splunk Cloud Platform or Splunk Enterprise) data, select the integration for the appropriate Splunk platform instance first, then select which index you want to query in Log Observer.
48

59
.. note:: You can only query indexes from one Splunk platform instance or Splunk Observability Cloud instance at a time. You can query Splunk platform indexes only if you have the appropriate role and permissions in the Splunk platform instance.
@@ -8,7 +12,7 @@
812

913
4. To search on a keyword, select the :guilabel:`Keyword` tab, type the keyword or phrase you want to search on, then press Enter. If you want to search on a field, select the :guilabel:`Fields` tab, enter the field name, then press Enter. To continue adding keywords or fields to the search, select :guilabel:`Add Filter`.
1014

11-
5. Next, select :guilabel:`Unlimited` or 150,000 results to determine the number of results you want to return on a single search.
15+
5. Next, select :guilabel:`Unlimited` or :guilabel:`150,000` results to determine the number of results you want to return on a single search.
1216

1317
6. Select :guilabel:`Run search`.
1418

0 commit comments

Comments
 (0)