I am looking to create a way to track multiple types of events across different sources. For example, where 'web' is a parent and things like 'attack', 'browser', 'misc', etc could be children. The c...
...panel that shows only the status tags. When I do |status count by tag it includes the name tags. Is it possible to categorize tags that are created through eventtypes so that I could do s...
Does anyone know if its possible as part of a workflow action that an event can be tagged?
I would love to be able to add a tag to specific events indicating the event was acknowledged after r...
...ms_cc_logs as an event. Manager > EventType > New, I paste it in, add a tag HTTP and call it HTTPError
Now if I do the following searches, I get 0 matching results:
index=cms_cc_logs e...
Splunk allows us to have a tag and an eventtype with the same name, so what exactly is the difference between an eventtype and a tag name?
We have defined “TransactionsAndroid” as an eventtype...
This is my search I am trying to use in an eventtype so I can tag my events.
index = mail
| eval Subject=coalesce(Subject,subjectx)
| search
Subject = "*NVEM Battery Alert*"
But i get t...
I always saw these "OS" and "Windows" tags on the eventtypes.conf and tags.conf. It's on the production environment and splunkbase applications even we're only using default Splunk CIM. OS- can b...
...ake a mistake in tag name when using a single tag in multiple eventtypes.
It appears for me that it is a base requirement for setting a field with side-registry values, like multi-select fields i...
Hello,
Is it possible to put spaces in tags of eventtypes ?
For example, I have an Eventtype for this log "[2011-04-22 22:28:17] INFO- (MessagingMain.java:161) GWMT0002I - BATCH PROCESS [J...
...n
(assuming that T3 > T2)
The idea would be to:
extract a list of unique scan types (S1, S2 in my case), called ScanTypes
and then do a last(ScanTypes) which would extract all the latest event...