Getting Data In

How create a tag based on field name ?

TanyaCnd
Loves-to-Learn Lots

Hi,

I am trying create tags based on index and field name .  Log:
1, User.field1, User.field2, User.field3

2, Admin.field1, Admin.field2, Admin.field3

3, Admin.field1, Admin.field2, Admin.field3

I want tag User.* fields with tag User and Admin.* with Admin. So, when we search with tag User only User events listed 

Thanks

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @TanyaCnd,

why don't you try to use two different tags?

e.g:

  • USER or ADMIN for the first one
  • FIELD1 FIELD2 FIELD3, etc... for the second one

then you can use them for your searches:

tag=ADMIN tag=FIELD1

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...