Knowledge Management

Why is tag creation not working, but the field/value pair is working?

HCadmins
Communicator

Hi Splunkers,

I have this search host=slc-p-cv01 sourcetype=csv that returns what I expect.

I am trying to make a tag called cv that contains this search.

So I create a tag, in the "Field value pair" I put the above search. In the Tag name, I put cv. I also gave the tag full permissions.

When I perform the search, it works. The tag returns nothing.

Thanks in advance!

Tags (2)
0 Karma
1 Solution

HCadmins
Communicator

This answer explains it well.

https://answers.splunk.com/answers/238355/what-are-the-definitions-of-tag-and-eventtype-and.html

I think what I need is an event type. Apparently a tag is a single key=value pair, where an eventtype can have multiple prepipe statements (which is what I have).

But, correct me if I am wrong, I could do this:

host=slc-p-cv01
tag=cv

sourcetype=csv
tag=cv

And it would be the same thing as

host=slc-p-cv01 sourcetype=csv
eventtype=cv

View solution in original post

0 Karma

HCadmins
Communicator

This answer explains it well.

https://answers.splunk.com/answers/238355/what-are-the-definitions-of-tag-and-eventtype-and.html

I think what I need is an event type. Apparently a tag is a single key=value pair, where an eventtype can have multiple prepipe statements (which is what I have).

But, correct me if I am wrong, I could do this:

host=slc-p-cv01
tag=cv

sourcetype=csv
tag=cv

And it would be the same thing as

host=slc-p-cv01 sourcetype=csv
eventtype=cv

0 Karma

HCadmins
Communicator

But my event type isn't working either.
alt text

0 Karma

HCadmins
Communicator

Ah, Got it! I had a typo.

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@HCadmins - Sounds like you resolved your issue? If yes, let me know and I will convert your comment as an Answer 🙂

0 Karma

HCadmins
Communicator

I did resolve my own issue. Thanks!

0 Karma

ddrillic
Ultra Champion

Just for curiosity, I'm not sure whether it should be a tag or an eventtype... it bothers me ; -)

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...