Hi,
I tagged several eventtypes and I'd like to know if it is possible to display a list of all these tags in the same way the "summary" page lists all the sources, sourcetypes and hosts.
Thanks.
You can query for a list of tags like this:
| rest /services/search/tags
In order to get a clickable entry point for kicking off a new search you'll need to build a panel in some view around those search results and define an appropriate drilldown.
Edit: If you can get the tags
command suggested by @somesoni2 to work then that's probably the nicer way.
You can query for a list of tags like this:
| rest /services/search/tags
In order to get a clickable entry point for kicking off a new search you'll need to build a panel in some view around those search results and define an appropriate drilldown.
Edit: If you can get the tags
command suggested by @somesoni2 to work then that's probably the nicer way.
Perfect ! Everything works fine, thanks.
For visibility issues, take a look at http://docs.splunk.com/Documentation/Splunk/latest/RESTAPI/RESTresources#servicesNS_endpoints
The - shouldn't be an issue.
By the way, they all contain the symbol -
, could this be a problem ?
rest
looks promising, except that I don't see any of my tags created in my application even if they are all world-readable.