Splunk Search

How do you 'Tag' based on a search?

andrewkenth
Communicator

I'm almost certian I used the wrong lingo but I'd like to essentially create a field based on search or regex, but I want my own predetermiend label to be the field value, not any of the contents of the raw log.

So, if I have a search like this:
index=myIndex sourcetype=mysourcetype "dude really did login"

I'd want all of thos results to be tagged with a field named "ServerEvent" and have the value be set to "LOGIN"

Alternativly I'd want a search like this:
index=myIndex sourcetype=mysourcetype "dude really did logout"

I'd want all of thos results to be tagged with a field named "ServerEvent" and have the value be set to "LOGOUT"

What is the most efficient way to do this in Splunk?

Tags (2)
0 Karma
1 Solution

aelliott
Motivator
0 Karma

aelliott
Motivator
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...