- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
multiple tag eval
metahaxorus
New Member
05-12-2020
11:33 AM
Hi I am creating a rule in enterprise security and am trying to use multiple tags.
| eval tag="prod_alert" and
| eval tag="risk_information"
What happens is every time the search runs the second tag overwrites the first tag. What do I need to do differently to use multiple tags in a rule?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
05-12-2020
12:21 PM
I've never seen tags set at search time. Typically, they're tested at search time using (tag=prod_alert AND tag=risk_information
, for example.
Setting tags usually is done via eventtypes, but not a search time.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
metahaxorus
New Member
05-12-2020
01:07 PM
Thank you for your comment it made me realize I was going in the wrong direction.
I didn't' need a tag. Instead, I made a search macro and set prod_alert=1 which allows me to search that field.
