Splunk Enterprise

help on tag

jip31
Motivator

hi

I have created a tag for the field "counter" called "a"

But when I run a search with tag=a or with tag::counter="a", there is no results

what is the problem please?

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

which search did you run:

tag="a"

or

index=your_index tag="a"

?

if you didn't inserted the index in the eventtype, you don't have it in the tag search and probably your index isn't in the default search path.

Try to add the index in the eventtype (also index=* if you don't want to associate the tag to a specific index) and try again.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

let me understand:

you created an eventtype like the following

counter="a"

and you associated to this eventtype a tag called "a" then, when you run a search where this field is present, you don't see the value "a" in the tag field,  or the search tag="a" hasn't any result, is it correct?

did you check if in the results of the search that you're analyzing the counter field is present?

then, are you sure about the exact value of tag? tag field is case sensitive.

Ciao.

Giuseppe

0 Karma

jip31
Motivator

hi

I can see the tag

jip31_0-1708072153946.png

But when I am doing  tag="a", i have no results

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

which search did you run:

tag="a"

or

index=your_index tag="a"

?

if you didn't inserted the index in the eventtype, you don't have it in the tag search and probably your index isn't in the default search path.

Try to add the index in the eventtype (also index=* if you don't want to associate the tag to a specific index) and try again.

Ciao.

Giuseppe

0 Karma

jip31
Motivator

index=mem tag=a return results but not tag=a 

you are right, when I add the tage add the index level tag=a works

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...