User Manual

 


Splunk Base

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Splunk Base

Splunk Base is the Web hub where Splunkers share their knowledge. It's a user-edited "folksonomy" that lists known event types, describes each event type in an editable wiki entry, and maps all uploaded event types and tags to one another.


Look up event

Search for eventtype::?14 on prodemo.splunk.com. Click Look up event in any one of the results.


Local event type


Splunk will pop open a new browser window with the Splunk Base entry for the event type.  Notice it has the global ID SP-CAAABHH, and has been tagged with "HEAD" by one Splunk Base member.   


Splunk Base




Share event

Event type tags can be uploaded to Splunk Base so other users can read them, and download them to their own servers. Click Share event to upload an event's tags to Splunk Base. A dialog box will pop up. If you need to protect private data in the event from being uploaded to Splunk Base, click the button labeled Anonymize my data.


[1]




Download

If you look up an event from your own Splunk Server instead of from our demo site, you can click the Download button in the upper right corner to install both the global ID and the tags for this event type on your server. Afterwards, all events of this type would be displayed on your server with the label "EVENTTYPE: !SP-CAAABHHH HEAD" rather than "EVENTTYPE::?14".

This documentation applies to the following versions of Splunk: 2.1 , 2.2 , 2.2.1 , 2.2.3 , 2.2.6 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!