Knowledge Management

Spaces in tags

woodreamz
New Member

Hello,

Is it possible to put spaces in tags of event types ?

For example, I have an Eventtype for this log "[2011-04-22 22:28:17] INFO- (MessagingMain.java:161) GWMT0002I - BATCH PROCESS [JNP02_S328] ENDED WITH STATUS: 1 => FAILED --> com.tdi.gw.system.MessagingMain - main". I use a eventtype and a tag to build "understandable" report with tags and not the full stacktrace. I want "Batch Failed" as tag for this eventtype but when you put a space, it is like you write 2 tags. Currently, I use "Batch_Failed" but if it is possible i prefer "Batch Failed".

Thanks

Tags (2)
0 Karma
1 Solution

hazekamp
Builder

Spaces are not allowed. I would recommend using a separator like dash or underscore. Per Splunk's CIM you may want to consider the use of two tags. The combination of these tags would eliminate the flexibility to search on these tags independent of each other.

See also: Common Information Model

View solution in original post

0 Karma

hazekamp
Builder

Spaces are not allowed. I would recommend using a separator like dash or underscore. Per Splunk's CIM you may want to consider the use of two tags. The combination of these tags would eliminate the flexibility to search on these tags independent of each other.

See also: Common Information Model

0 Karma

woodreamz
New Member

ok. I will use underscore 😕

0 Karma

ualbanytech
Path Finder

Maybe I'm missing something here but, not sure I see the problem. Give your event two tags.

Then just search on both:

Batch AND Failed

With two tags you could also perform searches like:

Batch (assuming you have non-batch events)

batch AND Success (assuming there are events tagged with Success)

OR maybe

batch AND NOT Failed

Although ugly, you could combined the words failedbatch or batchfailed.

0 Karma

woodreamz
New Member

I use tags mainly for simplify reports. I have 200 distinct errors to monitore and each error has an eventtype and tag. Many errors have the same tag to group them.
My problem is more an aesthitic problem than functionnal problem 🙂

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...