Knowledge Management

Spaces in tags

woodreamz
New Member

Hello,

Is it possible to put spaces in tags of event types ?

For example, I have an Eventtype for this log "[2011-04-22 22:28:17] INFO- (MessagingMain.java:161) GWMT0002I - BATCH PROCESS [JNP02_S328] ENDED WITH STATUS: 1 => FAILED --> com.tdi.gw.system.MessagingMain - main". I use a eventtype and a tag to build "understandable" report with tags and not the full stacktrace. I want "Batch Failed" as tag for this eventtype but when you put a space, it is like you write 2 tags. Currently, I use "Batch_Failed" but if it is possible i prefer "Batch Failed".

Thanks

Tags (2)
0 Karma
1 Solution

hazekamp
Builder

Spaces are not allowed. I would recommend using a separator like dash or underscore. Per Splunk's CIM you may want to consider the use of two tags. The combination of these tags would eliminate the flexibility to search on these tags independent of each other.

See also: Common Information Model

View solution in original post

0 Karma

hazekamp
Builder

Spaces are not allowed. I would recommend using a separator like dash or underscore. Per Splunk's CIM you may want to consider the use of two tags. The combination of these tags would eliminate the flexibility to search on these tags independent of each other.

See also: Common Information Model

0 Karma

woodreamz
New Member

ok. I will use underscore 😕

0 Karma

ualbanytech
Path Finder

Maybe I'm missing something here but, not sure I see the problem. Give your event two tags.

Then just search on both:

Batch AND Failed

With two tags you could also perform searches like:

Batch (assuming you have non-batch events)

batch AND Success (assuming there are events tagged with Success)

OR maybe

batch AND NOT Failed

Although ugly, you could combined the words failedbatch or batchfailed.

0 Karma

woodreamz
New Member

I use tags mainly for simplify reports. I have 200 distinct errors to monitore and each error has an eventtype and tag. Many errors have the same tag to group them.
My problem is more an aesthitic problem than functionnal problem 🙂

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...