Using event types to categorize results
An event type is essentially a simple search definition, with no pipes or commands.
To define an event type, first make a search. Let's search for the following:
sourcetype="impl_splunk_gen_SomeMoreLogs" logger=AuthClass
Let's say these events are login events. To make an event type, choose Settings and then Event types, as shown in the following screenshot:
This presents us with the Event types page where we view existing event types and, as we want to do here, create a new event:
Get Implementing Splunk - Second Edition now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.