Documentation: 3.0.2
Print Version Contents
This page last updated: 01/10/08 09:01am

Save event types via SplunkWeb

Most searches can be saved as an event type. There can be multiple event types for an event. You cannot create an event type with searches specifying an index, hosttag, eventtypetag, sourcetype or the pipe operator.

Configuration

To save a search as an event:

  • Type the search in the search box.
  • Click the arrow to the left of the search box.
  • Click Save as event type...

http://www.splunk.com/assets/doc-images/30_admin9_eventtypeweb/saveevent.jpg

The Save Event Type dialog box will pop up, pre-populated with your search terms.

http://www.splunk.com/assets/doc-images/30_admin9_eventtypeweb/saveeventtype.jpg

  • Name the event type.
  • Optionally add an event type tag.
  • Click the Save button.

You can now use your event type in searches:

eventtype=fooSearch

Example

For a detailed guide on best practices for creating event types in Splunk, check out this how to on Splunkbase.

Previous: punct::    |    Next: Configure eventtypes.conf

Comments

No comments have been submitted.

Log in to comment.