Splunk Search
Highlighted

List all tags

Explorer

Hi,

I tagged several eventtypes and I'd like to know if it is possible to display a list of all these tags in the same way the "summary" page lists all the sources, sourcetypes and hosts.

Thanks.

Tags (3)
0 Karma
Highlighted

Re: List all tags

SplunkTrust
SplunkTrust

You can query for a list of tags like this:

| rest /services/search/tags

In order to get a clickable entry point for kicking off a new search you'll need to build a panel in some view around those search results and define an appropriate drilldown.

Edit: If you can get the tags command suggested by @somesoni2 to work then that's probably the nicer way.

View solution in original post

Highlighted

Re: List all tags

Explorer

rest looks promising, except that I don't see any of my tags created in my application even if they are all world-readable.

0 Karma
Highlighted

Re: List all tags

Explorer

By the way, they all contain the symbol -, could this be a problem ?

0 Karma
Highlighted

Re: List all tags

SplunkTrust
SplunkTrust

For visibility issues, take a look at http://docs.splunk.com/Documentation/Splunk/latest/RESTAPI/RESTresources#servicesNS_endpoints

The - shouldn't be an issue.

0 Karma
Highlighted

Re: List all tags

Explorer

Perfect ! Everything works fine, thanks.

0 Karma