Splunk Search

Metadata filtered by eventtype

Communicator

Can I use eventtype=myevent with |metadata?

example: | metadata type=hosts | eventtype=group_A

I know tags work, but was curious if I could use eventtype as well.

Travis.

Tags (2)
0 Karma
1 Solution

SplunkTrust
SplunkTrust

No you cant im afraid.

Its akin to the fact that you cannot get the metadata command to tell you the hosts for a particular sourcetype, or the sources for a particular host etc...

but its even less potentially solvable than those more familiar problems, because for the eventtypes to match we'd have to have the event text and all fields extracted, and at that point splunk wouldnt be able to do anything less expensive than just running * | eventtype=group_A directly.

That said, I dont feel like I should answer this question without saying that you can pipe any results at all to the typer command, and it will apply all eventtypes to whatever the incoming result rows are, no matter whether or not they are 'events'. So you could use eventtypes if you piped to typer explicitly but they'd only be able to match on the fields that come out of the metadata command itself, and stuff that they themselves rexed out of those fields.

So this would be pretty limited and artificial, and a lot harder and less sensible than using either host tags or lookups. However eventtypes can do some amazing things and maybe you or someone else can spot how they could be useful here.

View solution in original post

SplunkTrust
SplunkTrust

No you cant im afraid.

Its akin to the fact that you cannot get the metadata command to tell you the hosts for a particular sourcetype, or the sources for a particular host etc...

but its even less potentially solvable than those more familiar problems, because for the eventtypes to match we'd have to have the event text and all fields extracted, and at that point splunk wouldnt be able to do anything less expensive than just running * | eventtype=group_A directly.

That said, I dont feel like I should answer this question without saying that you can pipe any results at all to the typer command, and it will apply all eventtypes to whatever the incoming result rows are, no matter whether or not they are 'events'. So you could use eventtypes if you piped to typer explicitly but they'd only be able to match on the fields that come out of the metadata command itself, and stuff that they themselves rexed out of those fields.

So this would be pretty limited and artificial, and a lot harder and less sensible than using either host tags or lookups. However eventtypes can do some amazing things and maybe you or someone else can spot how they could be useful here.

View solution in original post