Splunk Search

Can I place a TAG within a TAG?

mrcassout
New Member

Can I place a TAG within a TAG? I am creating different level TAGs, where I have a lower level containing specific server names and then a higher level that I would like to contain several lower level TAGs. Is this possible?

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mrcassout,
are you're speaking about tags or eventtypes? you can create eventtypes containing other eventtypes or tags, e.g.:
eventtype1 is index=my_index
eventtype2 is eventtype=eventtype1 sourcetype=sourcetypeA and it has associated tagA
eventtype3 is eventtype=eventtype1 sourcetype=sourcetypeB
eventtype4 is eventtype=eventtype1 TAG=tagA

Instead tags are a feature that you associate to an eventtype; to one eventtype you can associate none, one or more eventtypes or tags.

So you can create a tag inside another one working on eventtypes and associating tags to eventtypes

Ciao.
Giuseppe

0 Karma

efavreau
Motivator

Sort of. When you create a tag, you can create multiple tags in the same step by separating them with a comma. Your list of tags could be as creative as you want. i.e. webservers,webserverslinux,webserverslinuxralph
screenshot of a field, with a value of host=www2, and a blank tags filed, with a note reading, Enter a comma or space separated list of tags
For more information about how this would work, please see this Splunk Education video about Using Tags: https://www.splunk.com/view/SP-CAAAGYJ

###

If this reply helps you, an upvote would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...