Splunk Search

How do I add an eventtype to my search

vrmandadi
Builder

How do I add an eventtype to a search?

index=rgs_windows sourcetype=process_details instance != "Idle" instance !="_Total" NOT instance="svchost*" NOT Username = "NT_AUTHORITY*"  Username != "SYSTEM" |  rex field=instance "(?<instance>[^#]+e)" | rex field=instance "(?<t;instance>[^~]+)" | lookup host_info.csv host OUTPUTNEW ip |stats latest(ElapsedHours) AS "ElapsedHours", avg(AdjustedPercentCPU) AS "Average CPU %" ,latest(instance) AS Process by ip,host |rename ip as IP |table host, IP ,Process, ElapsedHours, "Average CPU %",

I want to add the eventtype below to the search above:

eventtype="windows_performance" ip="*" site_description="*" object="NVIDIA GPU" counter="% GPU Usage"| stats sparkline(avg(Value)) as Trend avg(Value) as Average, max(Value) as Peak, latest(Value) as Current, latest(_time) as "Last Updated" by ip

can anyone please help me? thank you

Tags (2)
0 Karma

jensonthottian
Contributor

eventtype="windows_performance" with your query.

Add this eventtype in the app you are using.

Go to settings ->Eventypes->new

marees123
Path Finder

worked for me... actually was searching how to add field "event type".. got an answer from your reply.

Thanks again.

0 Karma

vrmandadi
Builder

no the above event type is already a saved event type but i want to use that in the search query

0 Karma

jensonthottian
Contributor

can you confirm what eventtype="windows_performance" corresponds to ? the search query for the eventtype please.

0 Karma

vrmandadi
Builder

the event type displays the "gpu usage" field ..I want this field to be displayed along with other fields in search query

0 Karma
Get Updates on the Splunk Community!

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...