Search icon
Subscription
0
Cart icon
Close icon
You have no products in your basket yet
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Splunk Developer's Guide

You're reading from  Splunk Developer's Guide

Product type Book
Published in May 2015
Publisher
ISBN-13 9781785285295
Pages 180 pages
Edition 1st Edition
Languages
Author (1):
Kyle Smith Kyle Smith
Profile icon Kyle Smith

Enriched data


Naturally, when we talk about enriched data, we are talking about separating the isotopes of our data and storing them in secure storage, right? Nope! No weapons-grade data here! The term enriched data refers to adding extra context to raw data. Therefore, the data is then enriched. We will now cover event types, tags, and macros.

Event types

Event types are used to classify similar events into categories. Categorizing events is important because it can help you search through a large amount of data quickly, find patterns, or create specific alerts and searches. They are defined by users via the GUI or via the command line, or they are part of a prepackaged app. Event types can have permissions assigned to them so that only specific roles can view or edit them. Defined event types will show up in the user's Field List during a search in the GUI and, as such, can be modified and searched just as a normal field can be. Event types are defined by a Splunk search. Let's create an...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime}