Using event types to categorize results

An event type is essentially a simple search definition, with no pipes or commands.

To define an event type, first make a search. Let's search for the following:

sourcetype="impl_splunk_gen_SomeMoreLogs" logger=AuthClass 

Let's say these events are login events. To make an event type, choose Settings and then Event types, as shown in the following screenshot:

This presents us with the Event types page, where we view existing event types and, as we want to do here, create a new event:

First, click the ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.