Search Reference

 


typelearner

typelearner

Synopsis

Generates suggested eventtypes.

Syntax

typelearner [grouping-field] [grouping-maxlen]

Optional arguments

grouping-field
Syntax: <field>
Description: The field with values for typelearner to use when initially grouping events. Defaults to punct, the punctuation seen in _raw.
grouping-maxlen
Syntax: maxlen=<int>
Description: Determines how many characters in the grouping-field value to look at. If set to negative, the entire value of the grouping-field value is used to group events. Defaults to 15.

Description

Takes previous search results, and produces a list of promising searches that may be used as event-types. By default, the typelearner command initially groups events by the value of the grouping-field, and then further unifies and merges those groups, based on the keywords they contain.

Examples

Example 1: Have Splunk automatically discover and apply event types to search results

... | typelearner

See also

typer

Answers

Have questions? Visit Splunk Answers and see what questions and answers the Splunk community has using the typelearner command.

This documentation applies to the following versions of Splunk: 4.1 , 4.1.1 , 4.1.2 , 4.1.3 , 4.1.4 , 4.1.5 , 4.1.6 , 4.1.7 , 4.1.8 , 4.2 , 4.2.1 , 4.2.2 , 4.2.3 , 4.2.4 , 4.2.5 , 4.3 , 4.3.1 , 4.3.2 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.

Feedback submitted, thanks!