Knowledge Management

Spaces in tags

woodreamz
New Member

Hello,

Is it possible to put spaces in tags of event types ?

For example, I have an Eventtype for this log "[2011-04-22 22:28:17] INFO- (MessagingMain.java:161) GWMT0002I - BATCH PROCESS [JNP02_S328] ENDED WITH STATUS: 1 => FAILED --> com.tdi.gw.system.MessagingMain - main". I use a eventtype and a tag to build "understandable" report with tags and not the full stacktrace. I want "Batch Failed" as tag for this eventtype but when you put a space, it is like you write 2 tags. Currently, I use "Batch_Failed" but if it is possible i prefer "Batch Failed".

Thanks

Tags (2)
0 Karma
1 Solution

hazekamp
Builder

Spaces are not allowed. I would recommend using a separator like dash or underscore. Per Splunk's CIM you may want to consider the use of two tags. The combination of these tags would eliminate the flexibility to search on these tags independent of each other.

See also: Common Information Model

View solution in original post

0 Karma

hazekamp
Builder

Spaces are not allowed. I would recommend using a separator like dash or underscore. Per Splunk's CIM you may want to consider the use of two tags. The combination of these tags would eliminate the flexibility to search on these tags independent of each other.

See also: Common Information Model

0 Karma

woodreamz
New Member

ok. I will use underscore 😕

0 Karma

ualbanytech
Path Finder

Maybe I'm missing something here but, not sure I see the problem. Give your event two tags.

Then just search on both:

Batch AND Failed

With two tags you could also perform searches like:

Batch (assuming you have non-batch events)

batch AND Success (assuming there are events tagged with Success)

OR maybe

batch AND NOT Failed

Although ugly, you could combined the words failedbatch or batchfailed.

0 Karma

woodreamz
New Member

I use tags mainly for simplify reports. I have 200 distinct errors to monitore and each error has an eventtype and tag. Many errors have the same tag to group them.
My problem is more an aesthitic problem than functionnal problem 🙂

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...