Source Commands
Source commands produce a stream of events on their own.
They must be used as the first command in a search.
Available Source Commands
Command | Description |
---|---|
select | Scan raw events from indices based on keywords or terms |
rawselect | Similar to select but without additional processing |
generate | Generate dummy events for testing |
searchresult | Retrieve events from a previous search job |