Looping in Splunk

Is it possible to build programming loops in core Splunk? What would it look like? How would it work? Come see how a combination of key undocumented tricks have allowed us to do exactly that!

See how to use SPL commands with a sprinkling of hacks to loop:
Over rows
Over columns
Over values in multi-value fields
Over arbitrary counter that doesn’t exist (true program looping)


Gregg Woodcock


Video PowerPoint Github