Security

Why is the "field action menu" missing and how do I enable it?

mskjoldebrand
Explorer

I've been watching the new user tutorials and reached "Tags". However in my installation, I fail to find the "field action menu" which appears to the right of e.g. "host=www2" in this video here: https://www.youtube.com/watch?v=MCyOg66dbIk&index=12&list=PL59B00A6F603366EA

How do I provoke Splunk to show it?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

As you might expect, Splunk has changed a bit in the last four years. The "field action menu" is no longer there. Instead, click on the '>' in the 'i' column to expand the event. Then click in the Actions column for the field you wish to tag and select 'Edit tags'.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

mcederhage_splu
Splunk Employee
Splunk Employee

An answer that is loosely coupled.

One reason can be that the search you are executing is a realtime search. So change the time that you are using from realtime to something static

0 Karma

richgalloway
SplunkTrust
SplunkTrust

As you might expect, Splunk has changed a bit in the last four years. The "field action menu" is no longer there. Instead, click on the '>' in the 'i' column to expand the event. Then click in the Actions column for the field you wish to tag and select 'Edit tags'.

---
If this reply helps you, Karma would be appreciated.

mskjoldebrand
Explorer

Ah that is true. Thanks.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Which version of Splunk are you using?

---
If this reply helps you, Karma would be appreciated.
0 Karma

mskjoldebrand
Explorer

It is 6.5.1

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...