Security

Why is the "field action menu" missing and how do I enable it?

mskjoldebrand
Explorer

I've been watching the new user tutorials and reached "Tags". However in my installation, I fail to find the "field action menu" which appears to the right of e.g. "host=www2" in this video here: https://www.youtube.com/watch?v=MCyOg66dbIk&index=12&list=PL59B00A6F603366EA

How do I provoke Splunk to show it?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

As you might expect, Splunk has changed a bit in the last four years. The "field action menu" is no longer there. Instead, click on the '>' in the 'i' column to expand the event. Then click in the Actions column for the field you wish to tag and select 'Edit tags'.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

mcederhage_splu
Splunk Employee
Splunk Employee

An answer that is loosely coupled.

One reason can be that the search you are executing is a realtime search. So change the time that you are using from realtime to something static

0 Karma

richgalloway
SplunkTrust
SplunkTrust

As you might expect, Splunk has changed a bit in the last four years. The "field action menu" is no longer there. Instead, click on the '>' in the 'i' column to expand the event. Then click in the Actions column for the field you wish to tag and select 'Edit tags'.

---
If this reply helps you, Karma would be appreciated.

mskjoldebrand
Explorer

Ah that is true. Thanks.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Which version of Splunk are you using?

---
If this reply helps you, Karma would be appreciated.
0 Karma

mskjoldebrand
Explorer

It is 6.5.1

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...