Using event types to categorize results
An event type is essentially a simple search definition, with no pipes or commands. To define an event type, first make a search. Let's search for:
sourcetype="impl_splunk_gen" logger="AuthClass"
Let's say these events are login events. To make an event type, choose Event type... from the Create menu, as shown here:
This presents us with a dialog, where we can assign a Name string and optionally any Tags(s) to this event type, as shown in the following screenshot:
Let's name our event type login
.
We can now search ...
Get Implementing Splunk: Big Data Reporting and Development for Operational Intelligence now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.