Knowledge Management

Eventtype Challenges

daniel333
Builder

Hello,

I only Splunk on a limited basis, about once a month. our Splunk admin has over 300 "eventtypes" created. I am often teased for reinventing the wheel. I read through the eventypes list and there is just no way I can remember eventttype foo 4 months from now.

How do I request features to Splunk?
1) If I am writing a query which already is an eventtype, recommend it to me
2) better descriptions in the GUI of what a eventtype is
3) An option to highlite over an eventtype and a texttooltip or a popup which shows me the eventtypes definition.

Any other reading? Recommendations you can recommend on this?

Tags (1)
0 Karma

asimagu
Builder

Wow mate, that is a big bunch of eventtypes. The only thing I could recommend is using the search box in the upper right area when you go to Manager -> Eventtypes
Maybe this could help you too

http://docs.splunk.com/Documentation/Splunk/5.0.3/Knowledge/Defineeventtypes#Find_event_types

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...