Splunk Search

Metadata filtered by eventtype

thall79
Communicator

Can I use eventtype=myevent with |metadata?

example: | metadata type=hosts | eventtype=group_A

I know tags work, but was curious if I could use eventtype as well.

Travis.

Tags (2)
0 Karma
1 Solution

sideview
SplunkTrust
SplunkTrust

No you cant im afraid.

Its akin to the fact that you cannot get the metadata command to tell you the hosts for a particular sourcetype, or the sources for a particular host etc...

but its even less potentially solvable than those more familiar problems, because for the eventtypes to match we'd have to have the event text and all fields extracted, and at that point splunk wouldnt be able to do anything less expensive than just running * | eventtype=group_A directly.

That said, I dont feel like I should answer this question without saying that you can pipe any results at all to the typer command, and it will apply all eventtypes to whatever the incoming result rows are, no matter whether or not they are 'events'. So you could use eventtypes if you piped to typer explicitly but they'd only be able to match on the fields that come out of the metadata command itself, and stuff that they themselves rexed out of those fields.

So this would be pretty limited and artificial, and a lot harder and less sensible than using either host tags or lookups. However eventtypes can do some amazing things and maybe you or someone else can spot how they could be useful here.

View solution in original post

sideview
SplunkTrust
SplunkTrust

No you cant im afraid.

Its akin to the fact that you cannot get the metadata command to tell you the hosts for a particular sourcetype, or the sources for a particular host etc...

but its even less potentially solvable than those more familiar problems, because for the eventtypes to match we'd have to have the event text and all fields extracted, and at that point splunk wouldnt be able to do anything less expensive than just running * | eventtype=group_A directly.

That said, I dont feel like I should answer this question without saying that you can pipe any results at all to the typer command, and it will apply all eventtypes to whatever the incoming result rows are, no matter whether or not they are 'events'. So you could use eventtypes if you piped to typer explicitly but they'd only be able to match on the fields that come out of the metadata command itself, and stuff that they themselves rexed out of those fields.

So this would be pretty limited and artificial, and a lot harder and less sensible than using either host tags or lookups. However eventtypes can do some amazing things and maybe you or someone else can spot how they could be useful here.

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...