event type finder

noun

The findtypes command, which, when appended to a search, causes the search results to display as a breakdown of the most common groups of events found in the search results. These events are hierarchically ordered in terms of "coverage" (frequency), which enables you to identify categories of events that are subsets of larger groupings. Each discovered event grouping is also coupled with searches that can find just that set of events. You can test and save event types that are based on those discovered searches.

For more information

In the Knowledge Manager Manual:

In the Search Reference:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time