Creating event types and tagging
An event type is a way of categorizing data to make it easier to search. For example, we might want to get all authentication-type events from multiple log sources or we may tag all error messages with an error tag. In this section, we will explore event types for our BOTS
Dataset v1
.
An event type is a Splunk query. It is similar to the queries that we have executed so far in this chapter. Let’s look at an example. Suppose we wanted to get all authentication logs from our BOTS Dataset v1
. Where would we find those logs?
- We can search our dataset by using the
tag
keyword. Enter the following Splunk query in the search bar:index=botsv1 earliest=0 tag=authentication
- Click on the sourcetype field in Interesting fields on the left of the page. We will see that most of the authentication events come from the Windows logs (see Figure 3.27):
Figure 3.27 – Using tag=authentication in a search of the...