Build Event Type utility

noun

A tool which dynamically creates event types based on the analysis of a selected event. To access it, run a search, locate an event in the search results that might make a good event type, and then select Build event type from the event menu.

The Build Event Types utility enables you to try out different field/value pairings for the event type search, test potentially useful event types, and save the event types that perform well.

Related terms

For more information

In the Knowledge Manager Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time