When working with Splunk daily, you will find many of the tasks and searches you run are repeated on a periodic basis. As shown earlier, storing field extraction logic in a single place allows it to be reused in the future. Another way to make things easier and also shorten searches is to create Event Types. Event Types are not the same as events; an event is just a single instance of data. An Event Type is a grouping or classification of events meeting the same search criteria.
If you took a break between chapters, you will probably want to open up Splunk again. Then, execute a search command:
- Log in to the Splunk portal
- Click on your Destinations app
- Type this search in the search bar:
SPL> index=main ...