Knowledge Management

Event Type form tag name completion

sbarinov
Path Finder

Is there any way to make the event type form's field "tag" auto-complete tag names based on existing tags?
Are there any plans for this feature in upcoming releases?

It is very easy for one to make a mistake in tag name when using a single tag in multiple event types.
It appears for me that it is a base requirement for setting a field with side-registry values, like multi-select fields in Jira.

0 Karma

woodcock
Esteemed Legend

Why are you doing so much eventtype creation/modification? This is almost always a "once per sourcetype per datamodel" endeavor. Are you talking about inside of splunk or JIRA?

0 Karma

sbarinov
Path Finder

We are going to continuously create new event types when we discover new patterns of received log events.
We are linking alerts with event types via tags so the set of tags will be rarely changed but new event types will keep coming so we want to be sure that we assign correct tags to them so we don't miss new hits of the same pattern.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...