Splunk Enterprise

help on tag

jip31
Motivator

hi

I have created a tag for the field "counter" called "a"

But when I run a search with tag=a or with tag::counter="a", there is no results

what is the problem please?

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

which search did you run:

tag="a"

or

index=your_index tag="a"

?

if you didn't inserted the index in the eventtype, you don't have it in the tag search and probably your index isn't in the default search path.

Try to add the index in the eventtype (also index=* if you don't want to associate the tag to a specific index) and try again.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

let me understand:

you created an eventtype like the following

counter="a"

and you associated to this eventtype a tag called "a" then, when you run a search where this field is present, you don't see the value "a" in the tag field,  or the search tag="a" hasn't any result, is it correct?

did you check if in the results of the search that you're analyzing the counter field is present?

then, are you sure about the exact value of tag? tag field is case sensitive.

Ciao.

Giuseppe

0 Karma

jip31
Motivator

hi

I can see the tag

jip31_0-1708072153946.png

But when I am doing  tag="a", i have no results

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

which search did you run:

tag="a"

or

index=your_index tag="a"

?

if you didn't inserted the index in the eventtype, you don't have it in the tag search and probably your index isn't in the default search path.

Try to add the index in the eventtype (also index=* if you don't want to associate the tag to a specific index) and try again.

Ciao.

Giuseppe

0 Karma

jip31
Motivator

index=mem tag=a return results but not tag=a 

you are right, when I add the tage add the index level tag=a works

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...