当前位置:网站首页>Define event types in Splunk Web
Define event types in Splunk Web
2022-07-31 08:22:00 【shenghuiping2001】
1: 先看到这样一个界面,是不是就想把status=200, 和非200 的 event 区别出来:

2: 那么用上event type 就再好不过啦:
Steps:
Saving a search as an event type
In the Search view, run a search.
Click Save As and select Event Type.
Give the event type a unique Name.
(Optional) Add one or more comma-separated Tag(s).
You can apply the same tag to event types that produce similar results. A search that is just on that tag returns the set of events that collectively belong to those event types.(Optional) Select a Color.
This causes a band of color to appear at the start of the listing for any event that fits this event type. For example, this event matches an event type that has a Color of Purple.
You can change the color of an event type (or remove its color entirely) by editing it in Settings.(Optional) Give the event type a Priority.
Priority affects the display of events that match two or more event types. 1 is the best Priority and 10 is the worst. See About event type priorities.Click Save to save the new event type.
You can access the list of event types that you and other users have created at Settings > Event types.
Any event type that you create with this method also appears on the Event Types listing page in Settings. You can update the event type in the Event Types listing page.
参考文档:Define event types in Splunk Web - Splunk Documentation
利用 eventtype, 注意,不是source type, 就是对事件进行过滤,分类的条件可以在 search 语句中先体现出来:

边栏推荐
- tqdm库的使用
- 【MySQL功法】第5话 · SQL单表查询
- 2019 NeurIPS | Graph Convolutional Policy Network for Goal-Directed Molecular Graph Generation
- 2022杭电杯超级联赛3
- Golang-based swagger super intimate and super detailed usage guide [there are many pits]
- MySql 5.7.38下载安装教程 ,并实现在Navicat操作MySql
- Read Elephant Swap in one article, why does it bring such a high premium to ePLATO?
- skynet中一条消息从取出到处理完整流程(源码刨析)
- "The C language games" mine clearance
- SQL语句知识大全
猜你喜欢

Cloud server deployment web project

【问题记录】TypeError: eval() arg 1 must be a string, bytes or code object

SSM整合案例分析(详解)

期刊会议排名、信息检索网站推荐以及IEEE Latex模板下载

会话技术之Coookie && Session详解

力扣 593. 有效的正方形

SSM框架讲解(史上最详细的文章)

高并发高可用高性能的解决方案
![[MySQL exercises] Chapter 5 · SQL single table query](/img/11/66b4908ed8f253d599942f35bde96a.png)
[MySQL exercises] Chapter 5 · SQL single table query

How to restore data using mysql binlog
随机推荐
sqlmap使用教程大全命令大全(图文)
一、MySQL主从复制原理
35-Jenkins-Shared library application
【MySQL功法】第5话 · SQL单表查询
【C#】判断字符串中是否包含指定字符或字符串(Contains/IndexOf)
MySQL安装教程
日志导致线程Block的这些坑,你不得不防
剑指offer-解决面试题的思路
使用MySQL如何查询一年中每月的记录数
mysql 数据去重的三种方式[实战]
Read Elephant Swap in one article, why does it bring such a high premium to ePLATO?
tqdm库的使用
【MySQL功法】第4话 · 和kiko一起探索MySQL中的运算符
射频电路学习之滤波电路
NK - RTU980 burning bare-metal program
ScheduledExecutorService - 定时周期执行任务
Kotlin 优点
[Mini Program Project Development--Jingdong Mall] Custom Search Component of uni-app (Part 1)--Component UI
二维坐标工具API
【小程序项目开发 -- 京东商城】uni-app 商品分类页面(下)
