Security

Why is the "field action menu" missing and how do I enable it?

mskjoldebrand
Explorer

I've been watching the new user tutorials and reached "Tags". However in my installation, I fail to find the "field action menu" which appears to the right of e.g. "host=www2" in this video here: https://www.youtube.com/watch?v=MCyOg66dbIk&index=12&list=PL59B00A6F603366EA

How do I provoke Splunk to show it?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

As you might expect, Splunk has changed a bit in the last four years. The "field action menu" is no longer there. Instead, click on the '>' in the 'i' column to expand the event. Then click in the Actions column for the field you wish to tag and select 'Edit tags'.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

mcederhage_splu
Splunk Employee
Splunk Employee

An answer that is loosely coupled.

One reason can be that the search you are executing is a realtime search. So change the time that you are using from realtime to something static

0 Karma

richgalloway
SplunkTrust
SplunkTrust

As you might expect, Splunk has changed a bit in the last four years. The "field action menu" is no longer there. Instead, click on the '>' in the 'i' column to expand the event. Then click in the Actions column for the field you wish to tag and select 'Edit tags'.

---
If this reply helps you, Karma would be appreciated.

mskjoldebrand
Explorer

Ah that is true. Thanks.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Which version of Splunk are you using?

---
If this reply helps you, Karma would be appreciated.
0 Karma

mskjoldebrand
Explorer

It is 6.5.1

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...