Documentation: 3.2
Print Version Contents
This page last updated: 04/16/08 02:04pm

Event type templates

Create an event type based on a field via eventtypes.conf. For example:

[$NAME %$FIELD%]
$SEARCH_QUERY

Event type templates works a lot like macro searches: %$FIELD% gets filled in at search time with field=foo or field=bar, etc -- whatever the search query yields for that event type's field.

Configuration

When setting the name in eventtypes.conf, follow these specifications:

[$EVENTTYPE]

  • Header for the event type
  • $EVENTTYPE is the name of your event type.
  • You can have any number of event types, each represented by a stanza and any number of the following attribute/value pairs.
    • NOTE: If the name of the event type includes field names surrounded by the percent character (e.g. "%$FIELD%") then the value of $FIELD is substituted into the event type name for that event.

Example

[cisco-%code%]
cisco

If "code=432", this event type becomes "cisco-432".

Previous: Event type discovery    |    Next: Dynamic event rendering

Comments

No comments have been submitted.

Log in to comment.