Splunk Search

List all tags

bababou
Explorer

Hi,

I tagged several eventtypes and I'd like to know if it is possible to display a list of all these tags in the same way the "summary" page lists all the sources, sourcetypes and hosts.

Thanks.

Tags (3)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You can query for a list of tags like this:

| rest /services/search/tags

In order to get a clickable entry point for kicking off a new search you'll need to build a panel in some view around those search results and define an appropriate drilldown.

Edit: If you can get the tags command suggested by @somesoni2 to work then that's probably the nicer way.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You can query for a list of tags like this:

| rest /services/search/tags

In order to get a clickable entry point for kicking off a new search you'll need to build a panel in some view around those search results and define an appropriate drilldown.

Edit: If you can get the tags command suggested by @somesoni2 to work then that's probably the nicer way.

bababou
Explorer

Perfect ! Everything works fine, thanks.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

For visibility issues, take a look at http://docs.splunk.com/Documentation/Splunk/latest/RESTAPI/RESTresources#servicesNS_endpoints

The - shouldn't be an issue.

0 Karma

bababou
Explorer

By the way, they all contain the symbol -, could this be a problem ?

0 Karma

bababou
Explorer

rest looks promising, except that I don't see any of my tags created in my application even if they are all world-readable.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...