Knowledge Management

eventtypes combination

rakesh_498115
Motivator

Can we combine eventtypes based on a category? ie I have four eventtypes which fall into a specific category like purchase..so can I combine these four eventtypes into a single eventtype. If so, how i can i do it? And can you please provide an example for this.

Thnx.

Tags (1)
0 Karma
1 Solution

jerrad
Path Finder

event types are really just mini saved searches, so you could simply take your 4 event types and place them into a search like

eventtype=purchase-w OR eventtype=purchase-x OR eventtype=purchase-y OR eventtype=purchase-Z

Then save this is as an event type called "purchase" so the next time you search you could simply type eventtype=purchase

or you could just take all of the individual event types actual text and create one big search and save it as eventtype=purchase

If you would like to more easily handle this on a go forward basis you could start to tag your event types
http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Tageventtypes

View solution in original post

jerrad
Path Finder

event types are really just mini saved searches, so you could simply take your 4 event types and place them into a search like

eventtype=purchase-w OR eventtype=purchase-x OR eventtype=purchase-y OR eventtype=purchase-Z

Then save this is as an event type called "purchase" so the next time you search you could simply type eventtype=purchase

or you could just take all of the individual event types actual text and create one big search and save it as eventtype=purchase

If you would like to more easily handle this on a go forward basis you could start to tag your event types
http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Tageventtypes

Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...