<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Split event before apply profiling in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Split-event-before-apply-profiling/m-p/476067#M81694</link>
    <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;

&lt;P&gt;Thank you for your response. That's not what I'm asking. Due to the profiling, events which contain tag1 and tag2 at the same time, are already filtered and doesn't appear. What I need is to show events with tagged with (tag2) and (tag1tag2) at the same time. &lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Sep 2019 06:10:49 GMT</pubDate>
    <dc:creator>pbalbasm</dc:creator>
    <dc:date>2019-09-13T06:10:49Z</dc:date>
    <item>
      <title>Split event before apply profiling</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Split-event-before-apply-profiling/m-p/476065#M81692</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I have events tagged with &lt;EM&gt;tag1&lt;/EM&gt; and others with &lt;EM&gt;tag2&lt;/EM&gt;. In the &lt;EM&gt;restricted search terms of the search&lt;/EM&gt; in roles, I have &lt;CODE&gt;NOT tag=tag1&lt;/CODE&gt; so users can't see &lt;EM&gt;tag1&lt;/EM&gt; events. The problem is when an event contains both tags, so users cannot see the events and they should. &lt;/P&gt;

&lt;P&gt;Is there any way to split that events by tag in order that users are able to see those which contains &lt;EM&gt;tag2&lt;/EM&gt;?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 12:31:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Split-event-before-apply-profiling/m-p/476065#M81692</guid>
      <dc:creator>pbalbasm</dc:creator>
      <dc:date>2019-09-12T12:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Split event before apply profiling</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Split-event-before-apply-profiling/m-p/476066#M81693</link>
      <description>&lt;P&gt;Hi pbalbasm,&lt;BR /&gt;
let me understand: do you want a search with the condition tag=tag2?&lt;BR /&gt;
if yes, try something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=my_index tag=tag2
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 18:17:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Split-event-before-apply-profiling/m-p/476066#M81693</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-09-12T18:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: Split event before apply profiling</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Split-event-before-apply-profiling/m-p/476067#M81694</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;

&lt;P&gt;Thank you for your response. That's not what I'm asking. Due to the profiling, events which contain tag1 and tag2 at the same time, are already filtered and doesn't appear. What I need is to show events with tagged with (tag2) and (tag1tag2) at the same time. &lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 06:10:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Split-event-before-apply-profiling/m-p/476067#M81694</guid>
      <dc:creator>pbalbasm</dc:creator>
      <dc:date>2019-09-13T06:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Split event before apply profiling</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Split-event-before-apply-profiling/m-p/476068#M81695</link>
      <description>&lt;P&gt;ok, try this&lt;BR /&gt;
 index=my_index tag=tag2 OR (tag=tag1 tag=tag2)&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 06:56:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Split-event-before-apply-profiling/m-p/476068#M81695</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-09-13T06:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Split event before apply profiling</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Split-event-before-apply-profiling/m-p/476069#M81696</link>
      <description>&lt;P&gt;Hi, as I said that events doesn't appear, so it's not possible to manage in that way.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 07:27:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Split-event-before-apply-profiling/m-p/476069#M81696</guid>
      <dc:creator>pbalbasm</dc:creator>
      <dc:date>2019-09-13T07:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: Split event before apply profiling</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Split-event-before-apply-profiling/m-p/476070#M81697</link>
      <description>&lt;P&gt;Sorry!&lt;BR /&gt;
but if you use &lt;BR /&gt;
 index=my_index (tag=tag1 OR tag=tag2)&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;events with only tag1 are seen by users enabled for tag1,&lt;/LI&gt;
&lt;LI&gt;events with only tag2 are seen by users enabled for tag2,&lt;/LI&gt;
&lt;LI&gt;events with tag1 and tag2 should be seen by users enabled for tag1 or tag2,&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 07:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Split-event-before-apply-profiling/m-p/476070#M81697</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-09-13T07:46:36Z</dc:date>
    </item>
  </channel>
</rss>

