Documentation:
3.0.2
Most searches can be saved as an event type. There can be multiple event types for an event. You cannot create an event type with searches specifying an index, hosttag, eventtypetag, sourcetype or the pipe operator.
ConfigurationTo save a search as an event:

The Save Event Type dialog box will pop up, pre-populated with your search terms.

You can now use your event type in searches:
ExampleFor a detailed guide on best practices for creating event types in Splunk, check out this how to on Splunkbase.
Comments
No comments have been submitted.