Documentation:
3.3
Create an event type based on a field via eventtypes.conf. Edit eventtypes.conf in $SPLUNK_HOME/etc/system/local/, or your own custom application directory in $SPLUNK_HOME/etc/apps/. For more information on configuration files in general, see how configuration files work.
For example:
[$NAME %$FIELD%] $SEARCH_QUERY
Event type templates works a lot like macro searches: %$FIELD% gets filled in at search time with field=foo or field=bar, etc -- whatever the search query yields for that event type's field.
ConfigurationWhen setting the name in eventtypes.conf, follow these specifications:
[$EVENTTYPE]
[cisco-%code%] cisco
If "code=432", this event type becomes "cisco-432".
Comments
No comments have been submitted.