Splunk Base
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
Splunk Base
Splunk Base is the Web hub where Splunkers share their knowledge. It's a user-edited "folksonomy" that lists known event types, describes each event type in an editable wiki entry, and maps all uploaded event types and tags to one another.
Look up event
Search for eventtype::?14 on prodemo.splunk.com. Click Look up event in any one of the results.
Splunk will pop open a new browser window with the Splunk Base entry for the event type. Notice it has the global ID SP-CAAABHH, and has been tagged with "HEAD" by one Splunk Base member.
Event type tags can be uploaded to Splunk Base so other users can read them, and download them to their own servers. Click Share event to upload an event's tags to Splunk Base. A dialog box will pop up. If you need to protect private data in the event from being uploaded to Splunk Base, click the button labeled Anonymize my data.
Download
If you look up an event from your own Splunk Server instead of from our demo site, you can click the Download button in the upper right corner to install both the global ID and the tags for this event type on your server. Afterwards, all events of this type would be displayed on your server with the label "EVENTTYPE: !SP-CAAABHHH HEAD" rather than "EVENTTYPE::?14".
This documentation applies to the following versions of Splunk: 2.1 , 2.2 , 2.2.1 , 2.2.3 , 2.2.6 View the Article History for its revisions.