Knowledge Management

How to tag a field sourcetype from the search bar?

splunker12er
Motivator

I tried to tag the field sourcetype as suggested in the link :

[http://docs.splunk.com/Documentation/Splunk/6.1.2/SearchReference/Tags][1]

Examples
Example 1: Write tags for host and eventtype fields into tag::host and tag::eventtype.

... | tags host eventtype

index=* | tags sourcetype

but it doesnt created tag::sourcetype

Please help.. Am i missing something ..?

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Search for a value you want to tag, expand an event with that field value, look for the field you want to add a tag to, click the down-triangle to the right in the Actions column and select Edit Tags. That'll let you enter a tag for this field value.

After tagging you can then search by using tag=value or tag::fieldname=value.
You can edit and add more tags through the Settings as well by going into the Tags section.

See http://docs.splunk.com/Documentation/Splunk/6.1.3/Knowledge/Abouttagsandaliases for documentation on tagging your data.

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...