Using event types to categorize results

An event type is essentially a simple search definition, with no pipes or commands.

To define an event type, first make a search. Let's search for the following:

sourcetype="impl_splunk_gen_SomeMoreLogs" logger=AuthClass 

Let's say these events are login events. To make an event type, choose Settings and then Event types, as shown in the following screenshot:

This presents us with the Event types page, where we view existing event types and, as we want to do here, create a new event:

First, click the ...

Get Improving Your Splunk Skills now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.