Splunk Search

Metadata filtered by eventtype

thall79
Communicator

Can I use eventtype=myevent with |metadata?

example: | metadata type=hosts | eventtype=group_A

I know tags work, but was curious if I could use eventtype as well.

Travis.

Tags (2)
0 Karma
1 Solution

sideview
SplunkTrust
SplunkTrust

No you cant im afraid.

Its akin to the fact that you cannot get the metadata command to tell you the hosts for a particular sourcetype, or the sources for a particular host etc...

but its even less potentially solvable than those more familiar problems, because for the eventtypes to match we'd have to have the event text and all fields extracted, and at that point splunk wouldnt be able to do anything less expensive than just running * | eventtype=group_A directly.

That said, I dont feel like I should answer this question without saying that you can pipe any results at all to the typer command, and it will apply all eventtypes to whatever the incoming result rows are, no matter whether or not they are 'events'. So you could use eventtypes if you piped to typer explicitly but they'd only be able to match on the fields that come out of the metadata command itself, and stuff that they themselves rexed out of those fields.

So this would be pretty limited and artificial, and a lot harder and less sensible than using either host tags or lookups. However eventtypes can do some amazing things and maybe you or someone else can spot how they could be useful here.

View solution in original post

sideview
SplunkTrust
SplunkTrust

No you cant im afraid.

Its akin to the fact that you cannot get the metadata command to tell you the hosts for a particular sourcetype, or the sources for a particular host etc...

but its even less potentially solvable than those more familiar problems, because for the eventtypes to match we'd have to have the event text and all fields extracted, and at that point splunk wouldnt be able to do anything less expensive than just running * | eventtype=group_A directly.

That said, I dont feel like I should answer this question without saying that you can pipe any results at all to the typer command, and it will apply all eventtypes to whatever the incoming result rows are, no matter whether or not they are 'events'. So you could use eventtypes if you piped to typer explicitly but they'd only be able to match on the fields that come out of the metadata command itself, and stuff that they themselves rexed out of those fields.

So this would be pretty limited and artificial, and a lot harder and less sensible than using either host tags or lookups. However eventtypes can do some amazing things and maybe you or someone else can spot how they could be useful here.

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...