event type

noun

A type of knowledge object that enables you to categorize and label all the indexed events that match a specified search string. An event type has a name and an associated search. You can create your event types directly or use devices such as the typelearner, the event type finder, and the Build event types utility to help with the discovery and creation of event types.

After you set up event types, each time you run a search you can see the list of matching event types for each event in the results. You can tag event types, or search for matching events using the eventtype field.

For more information

In the Knowledge Manager Manual:

In the User Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time