Knowledge Management

Eventtype Challenges

daniel333
Builder

Hello,

I only Splunk on a limited basis, about once a month. our Splunk admin has over 300 "eventtypes" created. I am often teased for reinventing the wheel. I read through the eventypes list and there is just no way I can remember eventttype foo 4 months from now.

How do I request features to Splunk?
1) If I am writing a query which already is an eventtype, recommend it to me
2) better descriptions in the GUI of what a eventtype is
3) An option to highlite over an eventtype and a texttooltip or a popup which shows me the eventtypes definition.

Any other reading? Recommendations you can recommend on this?

Tags (1)
0 Karma

asimagu
Builder

Wow mate, that is a big bunch of eventtypes. The only thing I could recommend is using the search box in the upper right area when you go to Manager -> Eventtypes
Maybe this could help you too

http://docs.splunk.com/Documentation/Splunk/5.0.3/Knowledge/Defineeventtypes#Find_event_types

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...