Creating Tags and Event Types Flashcards
What are Tags?
Tags allow you to designate descriptive names for key-value pairs that make your data more understandable.
True or False: Tag values are case sensitive
True.
Tags can be used in a search with ______.
- A tag value
- A partial tag value with a wildcard
- A tag associated with a specific
What is the syntax for searching for a tag associated with a value on a specific field?
tag::<field>=<tag></tag></field>
Ex.
tag::user=privileged
What are the different ways to manage tags
- List by field value pair
- List by tag name
- All unique tag objects
*Note you will have different editing options depending on which option you choose.
What is the syntax when searching for a tag associated with a value?
tag=<tagname></tagname>
How do you search for a tag using a partial field value?
Using a wildcard (*)
Ex.
tag=p*
Tags make your data _____
More understandable and less ambiguous.
True or false: you can create one or more tags for any field/value combination.
True.
What are event types?
Event types allow you categorize events based on search terms.
How do you create an event type?
By saving a search as an event type using the drop down.
What is the difference between event types and saved reports?
Event Types:
- Categorize events based on a search string
- Use tags to organize
- Allow you to use the eventtype field within a search string
- Do NOT include a time range
Saved Reports:
- Used when the search criteria will not change
- When time range and formatting is needed
- Share with other Splunk users
- Add to dashboards
When multiple event types with different color values are assigned to the same event, what determines the color displayed for the event?
Priority determines the order of the event type listing in the expanded event.
Priority determines which event type color displays.
What is the difference between event types and saved searches?
Saved Search:
1. Search criteria will not change
2. Includes a time range and formatting of the results
3. Can be shared with Splunk users and added to dashboards
Event Types:
1. Categorize events based on a search string
2. Tag event types to organize data into categories
3. The eventtype field can be included in a search string
4. Does not include a time range
True or False: Event Types include a time range
False.