This documentation does not apply to the most recent version of Splunk.
This documentation applies to the following versions of Splunk: 3.2 , 3.2.1 , 3.2.2 , 3.2.3 , 3.2.4 , 3.2.5 , 3.2.6
Create an event type based on a field via eventtypes.conf. For example:
[$NAME %$FIELD%] $SEARCH_QUERY
Event type templates works a lot like macro searches: %$FIELD% gets filled in at search time with field=foo or field=bar, etc -- whatever the search query yields for that event type's field.
When setting the name in eventtypes.conf, follow these specifications:
[$EVENTTYPE]
$EVENTTYPE is the name of your event type.
[cisco-%code%] cisco
If "code=432", this event type becomes "cisco-432".