Knowledge Management

Why is tag creation not working, but the field/value pair is working?

HCadmins
Communicator

Hi Splunkers,

I have this search host=slc-p-cv01 sourcetype=csv that returns what I expect.

I am trying to make a tag called cv that contains this search.

So I create a tag, in the "Field value pair" I put the above search. In the Tag name, I put cv. I also gave the tag full permissions.

When I perform the search, it works. The tag returns nothing.

Thanks in advance!

Tags (2)
0 Karma
1 Solution

HCadmins
Communicator

This answer explains it well.

https://answers.splunk.com/answers/238355/what-are-the-definitions-of-tag-and-eventtype-and.html

I think what I need is an event type. Apparently a tag is a single key=value pair, where an eventtype can have multiple prepipe statements (which is what I have).

But, correct me if I am wrong, I could do this:

host=slc-p-cv01
tag=cv

sourcetype=csv
tag=cv

And it would be the same thing as

host=slc-p-cv01 sourcetype=csv
eventtype=cv

View solution in original post

0 Karma

HCadmins
Communicator

This answer explains it well.

https://answers.splunk.com/answers/238355/what-are-the-definitions-of-tag-and-eventtype-and.html

I think what I need is an event type. Apparently a tag is a single key=value pair, where an eventtype can have multiple prepipe statements (which is what I have).

But, correct me if I am wrong, I could do this:

host=slc-p-cv01
tag=cv

sourcetype=csv
tag=cv

And it would be the same thing as

host=slc-p-cv01 sourcetype=csv
eventtype=cv

0 Karma

HCadmins
Communicator

But my event type isn't working either.
alt text

0 Karma

HCadmins
Communicator

Ah, Got it! I had a typo.

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@HCadmins - Sounds like you resolved your issue? If yes, let me know and I will convert your comment as an Answer 🙂

0 Karma

HCadmins
Communicator

I did resolve my own issue. Thanks!

0 Karma

ddrillic
Ultra Champion

Just for curiosity, I'm not sure whether it should be a tag or an eventtype... it bothers me ; -)

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...