There are a few Splunk keyboard shortcuts that every Splunk power user should know. Two of the tips here allow you to quickly reformat search and dashboard code while the other expands macros.
Windows users should substitute CTRL for CMD in the examples below.
Quickly Reformat Your Splunk Searches
Did you know there is a shortcut key that can quickly reformat your Splunk searches?

Hit “CMD \” and your search will be nicely formatted!

Expand Macros
If you need to quickly see what a macro does you can use the “CMD SHIFT E” keyboard shortcut.

Formatting SimpleXML
As you copy, paste and edit sections of a SimpleXML dashboard it is easy for the formatting to go off. To quickly reformat the SimpleXML you can use the “CMD SHIFT F” keyboard shortcut. The screenshots below show before and after.


Further Tips
Write splunk searches like a pro and include comments – check this article to see how.
For 2021 we’ve committed to posting a new Splunk tip every week!
If you want to keep up to date on tips like the one above then sign up below:
Subscribe to our newsletter to receive regular updates from iDelta, including news and updates, information on upcoming events, and Splunk tips and tricks from our team of experts. You can also find us on Twitter and LinkedIn.