Getting Data In

How create a tag based on field name ?

TanyaCnd
Loves-to-Learn

Hi,

I am trying create tags based on index and field name .  Log:
1, User.field1, User.field2, User.field3

2, Admin.field1, Admin.field2, Admin.field3

3, Admin.field1, Admin.field2, Admin.field3

I want tag User.* fields with tag User and Admin.* with Admin. So, when we search with tag User only User events listed 

Thanks

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @TanyaCnd,

why don't you try to use two different tags?

e.g:

  • USER or ADMIN for the first one
  • FIELD1 FIELD2 FIELD3, etc... for the second one

then you can use them for your searches:

tag=ADMIN tag=FIELD1

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...