This documentation does not apply to the most recent version of Splunk.
This documentation applies to the following versions of Splunk: 3.3 , 3.3.1 , 3.3.2 , 3.3.3 , 3.3.4 , 3.4 , 3.4.1 , 3.4.2 , 3.4.3 , 3.4.5 , 3.4.6 , 3.4.8 , 3.4.9 , 3.4.10 , 3.4.11 , 3.4.12 , 3.4.13
Most searches can be saved as an event type. There can be multiple event types for an event. You cannot create an event type with searches specifying an index, hosttag, eventtypetag, sourcetype or the pipe operator. Any event types you create through Splunk Web are automatically added to $SPLUNK_HOME/etc/system/local/eventtypes.conf.
To save a search as an event:
The Save Event Type dialog box will pop up, pre-populated with your search terms.
You can now use your event type in searches: