Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Setting field based on eventtype

$
0
0
I do use **eventtypes.conf** to extract fields. Then in **tags.conf** I do set **warning=enable** for some of the fields. Some is **error** and other is **information**. In my search, this then shows up as **eventtype=xyz**, **tags=error** I would like to change this so I get a new field called **severity**. How do I set the **severity** field based on **eventtype**?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>