Data classification with Event Types

When working with Splunk daily, you will find many of the tasks and searches you run are repeated on a periodic basis. As shown earlier, storing field extraction logic in a single place allows it to be reused in the future. Another way to make things easier and also shorten searches is to create Event Types. Event Types are not the same as events; an event is just a single instance of data. An Event Type is a grouping or classification of events meeting the same search criteria.

If you took a break between chapters, you will probably want to open up Splunk again. Then, execute a search command:

  1. Log in to the Splunk portal
  2. Click on your Destinations app
  3. Type this search in the search bar:
SPL> index=main ...

Get Splunk 7 Essentials - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.