Splunk Search

Metadata filtered by eventtype

thall79
Communicator

Can I use eventtype=myevent with |metadata?

example: | metadata type=hosts | eventtype=group_A

I know tags work, but was curious if I could use eventtype as well.

Travis.

Tags (2)
0 Karma
1 Solution

sideview
SplunkTrust
SplunkTrust

No you cant im afraid.

Its akin to the fact that you cannot get the metadata command to tell you the hosts for a particular sourcetype, or the sources for a particular host etc...

but its even less potentially solvable than those more familiar problems, because for the eventtypes to match we'd have to have the event text and all fields extracted, and at that point splunk wouldnt be able to do anything less expensive than just running * | eventtype=group_A directly.

That said, I dont feel like I should answer this question without saying that you can pipe any results at all to the typer command, and it will apply all eventtypes to whatever the incoming result rows are, no matter whether or not they are 'events'. So you could use eventtypes if you piped to typer explicitly but they'd only be able to match on the fields that come out of the metadata command itself, and stuff that they themselves rexed out of those fields.

So this would be pretty limited and artificial, and a lot harder and less sensible than using either host tags or lookups. However eventtypes can do some amazing things and maybe you or someone else can spot how they could be useful here.

View solution in original post

sideview
SplunkTrust
SplunkTrust

No you cant im afraid.

Its akin to the fact that you cannot get the metadata command to tell you the hosts for a particular sourcetype, or the sources for a particular host etc...

but its even less potentially solvable than those more familiar problems, because for the eventtypes to match we'd have to have the event text and all fields extracted, and at that point splunk wouldnt be able to do anything less expensive than just running * | eventtype=group_A directly.

That said, I dont feel like I should answer this question without saying that you can pipe any results at all to the typer command, and it will apply all eventtypes to whatever the incoming result rows are, no matter whether or not they are 'events'. So you could use eventtypes if you piped to typer explicitly but they'd only be able to match on the fields that come out of the metadata command itself, and stuff that they themselves rexed out of those fields.

So this would be pretty limited and artificial, and a lot harder and less sensible than using either host tags or lookups. However eventtypes can do some amazing things and maybe you or someone else can spot how they could be useful here.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...