Hi @romainbouajila, the advantage to use eventtypes is that every updates has to be done in only one point, so if your hostnames chage you has to update only one eventtype. Anyway, are you sure that your eventtyper change frequently? it's a strange thing! If instead the problem is that you haven't a rule (e.g. italian servers tart with IT), you can list all the hosts of a group. e.g. eventtype italian_HT will be: (host=server1 OR host=server3 OR host=server4) as I said, if your list will change, you have to update only one eventtype. Otherwise, you could use a lookup correlating each host to a tag, but in this way you have to manage the lookup, in my opinion the choice dependa on the user that has to manage the list: for a Splunk admin it's easier to manage an eventtype, for a Splunk user it's easier to manage a lookup using Lookup Editor. Ciao. Giuseppe
... View more