Using tags to simplify search

Tags allow you to attach a marker to the fields and event types in Splunk. You can then search and report on these tags later. Let's attach a tag to a couple of users who are administrators. Start with the following search:

sourcetype="impl_splunk_gen" 
| top user 

This search gives us a list of our users such as ronnie, tuck, jarde, shelby, and so on:

Let's say that in our group, shelby and steve are administrators. Using a standard search, we can simply search for these two users like this:

sourcetype="impl_splunk_gen" (user=shelby OR user=steve) 

Searching for these two users while going forward will still work. ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.