I tried to tag the field sourcetype as suggested in the link :
[http://docs.splunk.com/Documentation/Splunk/6.1.2/SearchReference/Tags][1]
Examples
Example 1: Write tags for host and eventtype fields into tag::host and tag::eventtype.
... | tags host eventtype
index=* | tags sourcetype
but it doesnt created tag::sourcetype
Please help.. Am i missing something ..?
Search for a value you want to tag, expand an event with that field value, look for the field you want to add a tag to, click the down-triangle to the right in the Actions column and select Edit Tags. That'll let you enter a tag for this field value.
After tagging you can then search by using tag=value
or tag::fieldname=value
.
You can edit and add more tags through the Settings as well by going into the Tags section.
See http://docs.splunk.com/Documentation/Splunk/6.1.3/Knowledge/Abouttagsandaliases for documentation on tagging your data.