Save event types via SplunkWeb
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
Save event types via SplunkWeb
Most searches can be saved as an event type. There can be multiple event types for an event. You cannot create an event type with searches specifying an index, hosttag, eventtypetag, sourcetype or the pipe operator.
Configuration
To save a search as an event:
- Type the search in the search box.
- Click the arrow to the left of the search box.
- Click Save as event type...
The Save Event Type dialog box will pop up, pre-populated with your search terms.
- Name the event type.
- Optionally add an event type tag.
- Click the Save button.
You can now use your event type in searches:
eventtype=fooExample
For a detailed guide on best practices for creating event types in Splunk, check out this how to on Splunkbase.
This documentation applies to the following versions of Splunk: 3.0 , 3.0.1 , 3.0.2 , 3.1 , 3.1.1 , 3.1.2 , 3.1.3 , 3.1.4 View the Article History for its revisions.

