Documentation: 3.3
Print Version Contents
This page last updated: 05/16/08 04:05pm

Event type templates

Create an event type based on a field via eventtypes.conf. Edit eventtypes.conf in $SPLUNK_HOME/etc/system/local/, or your own custom application directory in $SPLUNK_HOME/etc/apps/. For more information on configuration files in general, see how configuration files work.

For example:

[$NAME %$FIELD%]
$SEARCH_QUERY

Event type templates works a lot like macro searches: %$FIELD% gets filled in at search time with field=foo or field=bar, etc -- whatever the search query yields for that event type's field.

Configuration

When setting the name in eventtypes.conf, follow these specifications:

[$EVENTTYPE]

  • Header for the event type
  • $EVENTTYPE is the name of your event type.
  • You can have any number of event types, each represented by a stanza and any number of the following attribute/value pairs.
    • NOTE: If the name of the event type includes field names surrounded by the percent character (e.g. "%$FIELD%") then the value of $FIELD is substituted into the event type name for that event.

Example

[cisco-%code%]
cisco

If "code=432", this event type becomes "cisco-432".

Previous: Event type discovery    |    Next: Dynamic event rendering

Comments

No comments have been submitted.

Log in to comment.