当前位置:网站首页>Define event types in Splunk Web
Define event types in Splunk Web
2022-07-31 08:22:00 【shenghuiping2001】
1: 先看到这样一个界面,是不是就想把status=200, 和非200 的 event 区别出来:
2: 那么用上event type 就再好不过啦:
Steps:
Saving a search as an event type
In the Search view, run a search.
Click Save As and select Event Type.
Give the event type a unique Name.
(Optional) Add one or more comma-separated Tag(s).
You can apply the same tag to event types that produce similar results. A search that is just on that tag returns the set of events that collectively belong to those event types.(Optional) Select a Color.
This causes a band of color to appear at the start of the listing for any event that fits this event type. For example, this event matches an event type that has a Color of Purple.
You can change the color of an event type (or remove its color entirely) by editing it in Settings.(Optional) Give the event type a Priority.
Priority affects the display of events that match two or more event types. 1 is the best Priority and 10 is the worst. See About event type priorities.Click Save to save the new event type.
You can access the list of event types that you and other users have created at Settings > Event types.
Any event type that you create with this method also appears on the Event Types listing page in Settings. You can update the event type in the Event Types listing page.
参考文档:Define event types in Splunk Web - Splunk Documentation
利用 eventtype, 注意,不是source type, 就是对事件进行过滤,分类的条件可以在 search 语句中先体现出来:
边栏推荐
猜你喜欢
随机推荐
科目三:右转弯
C# 正则表达式汇总
C语言三子棋(井字棋)小游戏
Aleo Testnet3规划大纲
免安装版的Mysql安装与配置——详细教程
35-Jenkins-共享库应用
【小程序项目开发 -- 京东商城】uni-app 商品分类页面(下)
A, MySQL principle of master-slave replication
The first part of the R language
【插值与拟合】
35-Jenkins-Shared library application
高并发高可用高性能的解决方案
【小程序项目开发--京东商城】uni-app之自定义搜索组件(上)-- 组件UI
如何在 Linux 上安装 MySQL
Cloud server deployment web project
ScheduledExecutorService - 定时周期执行任务
[Mini Program Project Development--Jingdong Mall] Custom Search Component of uni-app (Part 1)--Component UI
SSM整合案例分析(详解)
哪些字符串会被FastJson解析为null呢
数组every和some方法的区别?