Knowledge Management

Why is tag creation not working, but the field/value pair is working?

HCadmins
Communicator

Hi Splunkers,

I have this search host=slc-p-cv01 sourcetype=csv that returns what I expect.

I am trying to make a tag called cv that contains this search.

So I create a tag, in the "Field value pair" I put the above search. In the Tag name, I put cv. I also gave the tag full permissions.

When I perform the search, it works. The tag returns nothing.

Thanks in advance!

Tags (2)
0 Karma
1 Solution

HCadmins
Communicator

This answer explains it well.

https://answers.splunk.com/answers/238355/what-are-the-definitions-of-tag-and-eventtype-and.html

I think what I need is an event type. Apparently a tag is a single key=value pair, where an eventtype can have multiple prepipe statements (which is what I have).

But, correct me if I am wrong, I could do this:

host=slc-p-cv01
tag=cv

sourcetype=csv
tag=cv

And it would be the same thing as

host=slc-p-cv01 sourcetype=csv
eventtype=cv

View solution in original post

0 Karma

HCadmins
Communicator

This answer explains it well.

https://answers.splunk.com/answers/238355/what-are-the-definitions-of-tag-and-eventtype-and.html

I think what I need is an event type. Apparently a tag is a single key=value pair, where an eventtype can have multiple prepipe statements (which is what I have).

But, correct me if I am wrong, I could do this:

host=slc-p-cv01
tag=cv

sourcetype=csv
tag=cv

And it would be the same thing as

host=slc-p-cv01 sourcetype=csv
eventtype=cv

0 Karma

HCadmins
Communicator

But my event type isn't working either.
alt text

0 Karma

HCadmins
Communicator

Ah, Got it! I had a typo.

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@HCadmins - Sounds like you resolved your issue? If yes, let me know and I will convert your comment as an Answer 🙂

0 Karma

HCadmins
Communicator

I did resolve my own issue. Thanks!

0 Karma

ddrillic
Ultra Champion

Just for curiosity, I'm not sure whether it should be a tag or an eventtype... it bothers me ; -)

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...