Knowledge Management

Why is tag creation not working, but the field/value pair is working?

HCadmins
Communicator

Hi Splunkers,

I have this search host=slc-p-cv01 sourcetype=csv that returns what I expect.

I am trying to make a tag called cv that contains this search.

So I create a tag, in the "Field value pair" I put the above search. In the Tag name, I put cv. I also gave the tag full permissions.

When I perform the search, it works. The tag returns nothing.

Thanks in advance!

Tags (2)
0 Karma
1 Solution

HCadmins
Communicator

This answer explains it well.

https://answers.splunk.com/answers/238355/what-are-the-definitions-of-tag-and-eventtype-and.html

I think what I need is an event type. Apparently a tag is a single key=value pair, where an eventtype can have multiple prepipe statements (which is what I have).

But, correct me if I am wrong, I could do this:

host=slc-p-cv01
tag=cv

sourcetype=csv
tag=cv

And it would be the same thing as

host=slc-p-cv01 sourcetype=csv
eventtype=cv

View solution in original post

0 Karma

HCadmins
Communicator

This answer explains it well.

https://answers.splunk.com/answers/238355/what-are-the-definitions-of-tag-and-eventtype-and.html

I think what I need is an event type. Apparently a tag is a single key=value pair, where an eventtype can have multiple prepipe statements (which is what I have).

But, correct me if I am wrong, I could do this:

host=slc-p-cv01
tag=cv

sourcetype=csv
tag=cv

And it would be the same thing as

host=slc-p-cv01 sourcetype=csv
eventtype=cv

0 Karma

HCadmins
Communicator

But my event type isn't working either.
alt text

0 Karma

HCadmins
Communicator

Ah, Got it! I had a typo.

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@HCadmins - Sounds like you resolved your issue? If yes, let me know and I will convert your comment as an Answer 🙂

0 Karma

HCadmins
Communicator

I did resolve my own issue. Thanks!

0 Karma

ddrillic
Ultra Champion

Just for curiosity, I'm not sure whether it should be a tag or an eventtype... it bothers me ; -)

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...