This is not current Splunk documentation.
Splunk 3.4.2 is the latest version. Only use this page with older Splunk 2.0.x.

Splunk User Manual (Splunk v2.0)

Tutorial

Tags

Tags are how Splunkers around the world share their knowledge about IT events.

How Tags Work

It's just like tagging photos on Flickr.

  • A single event type can have an unlimited number of tags.
  • A single tag can be applied to an unlimited number of event types.

For example, there are nearly 400 event types at Splunk Base tagged Websphere, and 100-plus tagged Apache.

Example

Let's look at event type SP-CAAADUP again. It's been tagged with at least three different tags—Apache, listener, and network. Clicking each of those tags in Splunk Base shows a different slice of event types that match each tag, so you can see where the event type fits into the grand scheme of IT data.

Splunk Professional Users

Splunk Professional users without Power User or Admin status can view and search tags and look them up at \ Splunk Base. They can't download tags to update the local Splunk index, though.

Comments

No comments have been submitted.

close

Flash required to play this video.

Click here to download the free Flash Player.

Description:

Permalink: