Module 9: Working with Tags and Event Types Flashcards

1
Q

Describe what a tag is?

A
  • Tags are like nicknames that you create for related field/value pairs
  • Tags make your data more understandable and less ambiguous
  • You can create one or more tags for any field/value combination
  • Tags are case sensitive
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How do you create a tag?

A
  1. Click on the arrow for event details
  2. Under Actions, click the down arrow
  3. Select Edit TAgs
  4. Name the tags, separated by commas
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When tagged field/value pairs are selected, the tags appear how?

A
  • In the results as tags

- In parentheses next to the associated field/value pairs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How do you use tags in a search?

A

Use the syntax: tag=

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

To search for a tag associated with a value:

A
  • tag=

example: tag=privileged

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

To search for a tag associated with a value on a specific field:

A
  • tag::=

example: tag::user=privileged

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

To search for a tag using a partial field value:

A
  • use (*) wildcard

example: tag=p*

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do you manage tags when list by field value pair?

A
  • settings
  • tags
  • list by field value pair
    You can also:
  • edit permissions
  • disable all tags for pair - disables the tag in searches and prevents it from being listed under List by Tag Name and All unique tag objects
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How do you add/change the tag name?

A

Click list by field value pair to add another tag or change the name of the tag

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How do you add/change the field value pair?

A

Click list by tag name to add or edit the field value pair for the tag

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Describe event types?

A
  • A method of categorizing events based on a search
  • A useful method for institutional knowledge capturing and sharing
  • Can be tagged to group similar types of events
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How do you create an event type from the search page?

A
  1. Run a search and verify that all results meet your event type criteria
  2. From the save as menu, select event type
  3. Provide a name for your event type (name should not contain spaces)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How would you use the event type builder?

A
  1. From the event details, select event actions > build event type
  2. Refine the criteria for your event type such as
    - search string
    - field values
    - tags
  3. Verify your selections and click save
    Must be a basic search (cannot contain pipes or subsearches)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How would you verify the event type?

A

Search for eventtype=web_error

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Where does the event type display?

A

In the Fields sidebar and can be added as a selected field

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

When does Splunk evaluate the events?

A

Splunk evaluates the events and applies the appropriate event types at search time

17
Q

What can you do when using the fields sidebar?

A

You can easily view the individual event types, the number of events, and percentage

18
Q

How can you tag event types?

A

You can tag event types 2 ways:

  1. Settings > Event types
  2. Event details > Actions
19
Q

How do event types compare to saved reports?

A

Event type:

  • categorize events based on a search string
  • tag event types to organize data into categories
  • the eventtype field can be included in a search string
  • does not include a time range

Saved Reports:

  • search criteria will not change
  • includes a time range and formatting of the results
  • can be shared with Splunk users and added to dashboards