Splunk Enterprise

help on tag

jip31
Motivator

hi

I have created a tag for the field "counter" called "a"

But when I run a search with tag=a or with tag::counter="a", there is no results

what is the problem please?

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

which search did you run:

tag="a"

or

index=your_index tag="a"

?

if you didn't inserted the index in the eventtype, you don't have it in the tag search and probably your index isn't in the default search path.

Try to add the index in the eventtype (also index=* if you don't want to associate the tag to a specific index) and try again.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

let me understand:

you created an eventtype like the following

counter="a"

and you associated to this eventtype a tag called "a" then, when you run a search where this field is present, you don't see the value "a" in the tag field,  or the search tag="a" hasn't any result, is it correct?

did you check if in the results of the search that you're analyzing the counter field is present?

then, are you sure about the exact value of tag? tag field is case sensitive.

Ciao.

Giuseppe

0 Karma

jip31
Motivator

hi

I can see the tag

jip31_0-1708072153946.png

But when I am doing  tag="a", i have no results

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

which search did you run:

tag="a"

or

index=your_index tag="a"

?

if you didn't inserted the index in the eventtype, you don't have it in the tag search and probably your index isn't in the default search path.

Try to add the index in the eventtype (also index=* if you don't want to associate the tag to a specific index) and try again.

Ciao.

Giuseppe

0 Karma

jip31
Motivator

index=mem tag=a return results but not tag=a 

you are right, when I add the tage add the index level tag=a works

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jip31,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...