Using event types to categorize results

An event type is essentially a simple search definition, with no pipes or commands.

To define an event type, first make a search. Let's search for the following:

sourcetype="impl_splunk_gen_SomeMoreLogs" logger=AuthClass

Let's say these events are login events. To make an event type, choose Settings and then Event types, as shown in the following screenshot:

Using event types to categorize results

This presents us with the Event types page where we view existing event types and, as we want to do here, create a new event:

Using event types to categorize results

Image showing the Splunk Event ...

Get Implementing Splunk - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.