Event type
An event type is a user-defined field that represents a category of events that can all be matched by the same search string. When you run a search that returns a useful set of events, you can save that search string—or the reusable parts of it—as an event type, and use that event type in future searches. This is particularly useful for leveraging event types in things such as saved searches, reports, and dashboards if the event type contains one or more indexes, sources, or source types that can be changed in one place (the event type) instead of updating all the tools that use this same search criteria.
You can view the event types that Splunk provides out of the box by clicking Settings | Event types; one example you'll see ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access