I have a list of URLs in my website that is critical. So, I have marked all those URLs with a
tag::critical using eventtype. However, I am unable to use
tag field to filter data within the datamodel. So, I want to setup a field called
content_priority that should have value of
"critical" if the event has a
critical tag , else set the field value to
I have configured a calculated field with following eval expression:
However it does not seem to work at all. So, I am stuck with it now.
Any guidance would be much helpful and appreciated.
which data model are you using? If you speaking about Splunk CIM ( https://docs.splunk.com/Documentation/CIM/latest/User/Overview ) then you can use only predefined tags. If you want to use some custom tags like critical, then you need to extend (i.e. modify) the data model - this can be easy done by cloning a suitable data model: https://docs.splunk.com/Documentation/Splunk/8.0.3/Knowledge/Managedatamodels#Clone_a_data_model
If you use custom data model already then you have to check your data model if such tag and this field (content_priority) are included.
I am using Web data model as of now. I didn’t know that we can’t use external tags within the data model queries.
However, my main concern is “could I setup a calculated field in
index=DMZ based on tag values?”