Splunk Search

Metadata filtered by eventtype

thall79
Communicator

Can I use eventtype=myevent with |metadata?

example: | metadata type=hosts | eventtype=group_A

I know tags work, but was curious if I could use eventtype as well.

Travis.

Tags (2)
0 Karma
1 Solution

sideview
SplunkTrust
SplunkTrust

No you cant im afraid.

Its akin to the fact that you cannot get the metadata command to tell you the hosts for a particular sourcetype, or the sources for a particular host etc...

but its even less potentially solvable than those more familiar problems, because for the eventtypes to match we'd have to have the event text and all fields extracted, and at that point splunk wouldnt be able to do anything less expensive than just running * | eventtype=group_A directly.

That said, I dont feel like I should answer this question without saying that you can pipe any results at all to the typer command, and it will apply all eventtypes to whatever the incoming result rows are, no matter whether or not they are 'events'. So you could use eventtypes if you piped to typer explicitly but they'd only be able to match on the fields that come out of the metadata command itself, and stuff that they themselves rexed out of those fields.

So this would be pretty limited and artificial, and a lot harder and less sensible than using either host tags or lookups. However eventtypes can do some amazing things and maybe you or someone else can spot how they could be useful here.

View solution in original post

sideview
SplunkTrust
SplunkTrust

No you cant im afraid.

Its akin to the fact that you cannot get the metadata command to tell you the hosts for a particular sourcetype, or the sources for a particular host etc...

but its even less potentially solvable than those more familiar problems, because for the eventtypes to match we'd have to have the event text and all fields extracted, and at that point splunk wouldnt be able to do anything less expensive than just running * | eventtype=group_A directly.

That said, I dont feel like I should answer this question without saying that you can pipe any results at all to the typer command, and it will apply all eventtypes to whatever the incoming result rows are, no matter whether or not they are 'events'. So you could use eventtypes if you piped to typer explicitly but they'd only be able to match on the fields that come out of the metadata command itself, and stuff that they themselves rexed out of those fields.

So this would be pretty limited and artificial, and a lot harder and less sensible than using either host tags or lookups. However eventtypes can do some amazing things and maybe you or someone else can spot how they could be useful here.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...