Splunk Enterprise

help on tag

jip31
Motivator

hi

I have created a tag for the field "counter" called "a"

But when I run a search with tag=a or with tag::counter="a", there is no results

what is the problem please?

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

which search did you run:

tag="a"

or

index=your_index tag="a"

?

if you didn't inserted the index in the eventtype, you don't have it in the tag search and probably your index isn't in the default search path.

Try to add the index in the eventtype (also index=* if you don't want to associate the tag to a specific index) and try again.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

let me understand:

you created an eventtype like the following

counter="a"

and you associated to this eventtype a tag called "a" then, when you run a search where this field is present, you don't see the value "a" in the tag field,  or the search tag="a" hasn't any result, is it correct?

did you check if in the results of the search that you're analyzing the counter field is present?

then, are you sure about the exact value of tag? tag field is case sensitive.

Ciao.

Giuseppe

0 Karma

jip31
Motivator

hi

I can see the tag

jip31_0-1708072153946.png

But when I am doing  tag="a", i have no results

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

which search did you run:

tag="a"

or

index=your_index tag="a"

?

if you didn't inserted the index in the eventtype, you don't have it in the tag search and probably your index isn't in the default search path.

Try to add the index in the eventtype (also index=* if you don't want to associate the tag to a specific index) and try again.

Ciao.

Giuseppe

0 Karma

jip31
Motivator

index=mem tag=a return results but not tag=a 

you are right, when I add the tage add the index level tag=a works

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...