Knowledge Management

Search for data that has not been tagged

sarahw3
Explorer

I have just created 71 eventtypes and I want to see if I left any out. In each eventtype I gave it a tag. In the search, is there a way to search for my data that does not have a tag?

0 Karma
1 Solution

DalJeanis
SplunkTrust
SplunkTrust

Later in the search it looks like this...

| where isnull(tag)

I believe on the initial search it would be...

 tag!=*

... or ...

NOT tag=*

View solution in original post

0 Karma

DalJeanis
SplunkTrust
SplunkTrust

Later in the search it looks like this...

| where isnull(tag)

I believe on the initial search it would be...

 tag!=*

... or ...

NOT tag=*
0 Karma

sarahw3
Explorer

The isnull one worked perfectly! Thank you!

Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of the streaming infrastructure for Splunk APM and Splunk RUM in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...