All Apps and Add-ons

Why unable to see tag and tag::eventtype fields and others are getting populated when typing index=windows?

AyushiSrivas
Loves-to-Learn

I have installed Splunk TA Windows Add-on, still I am unable to see tag and tag::eventtype fields, when typing  index=windows but rest other are getting populated. Therefore unable to use "| savedsearch DA-ITSI-OS-OS_Hosts_Search" for importing the entities as it required tag field Please help me here.

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...

Stay Connected: Your Guide to February Tech Talks, Office Hours, and Webinars!

💌Keep the new year’s momentum going with our February lineup of Community Office Hours, Tech Talks, ...