Is it possible to auto-tag a field from the results of a search from the cli or the search bar? Something like:
"search color=scarlet OR color=crimson | tag tag::color=red"
Hi,
It's not possible to do it automatically you can do it through the Splunk Web interface:
Also if you are running 4.3 you can do some dynamic tagging from the event viewer data:
See http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Tagthehostfield
Thanks,
Kate