Getting Data In

How create a tag based on field name ?

TanyaCnd
Loves-to-Learn Lots

Hi,

I am trying create tags based on index and field name .  Log:
1, User.field1, User.field2, User.field3

2, Admin.field1, Admin.field2, Admin.field3

3, Admin.field1, Admin.field2, Admin.field3

I want tag User.* fields with tag User and Admin.* with Admin. So, when we search with tag User only User events listed 

Thanks

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @TanyaCnd,

why don't you try to use two different tags?

e.g:

  • USER or ADMIN for the first one
  • FIELD1 FIELD2 FIELD3, etc... for the second one

then you can use them for your searches:

tag=ADMIN tag=FIELD1

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...