Hi Rich, This is where my newness will likely shine, but when you say "category of event" do you just mean examples of the different types of events in the index that I am searching? If so, the following are some examples: Currently we have an index where we are sending custom formatted events via a python script based on calculated data form Corvil logs. We also sent in some test events, all of which include the word "test" somewhere in the event. The base search I am using to try and test the tags is simply 'index="nameofourindex" test. This returns approx. a dozen events that look like either of the following (note: event #1 has two fields that are pipe separated, whereas event#2 just has a string of "test log" in the raw text): Event Example 1: Time (date/Time) : Event (Text=Monitoring Log Test| Type=LOG4) Event Example 2: Time (date/Time) : test log The rest of the events in the index are the Corvil data events that have Time (date/Time) and then approx. 16 or so pipe separated fields. I selected events within the 12 that contain the word "test" and added the "snooze" label to those with "Type=LOG4", "Type=LOG5", etc. so that all the "test" events have a "snooze" label with the exception of those two that just have "test log" as raw text, which have no labels. If I add NOT tag=snooze then I only get the two events that have "test" but not a "snooze" label (so that works) If I change this to NOT tag=foo (where foo is not a currently used tag) I get zero results (when I would think I should get all 12 events that have "test" Apologies if my explanation is confusing or I am not providing the info you need, I appreciate your help and patience.
... View more