An event type is essentially a simple search definition, with no pipes or commands.
To define an event type, first make a search. Let's search for the following:
Let's say these events are login events. To make an event type, choose Settings and then Event types, as shown in the following screenshot:
This presents us with the Event types page, where we view existing event types and, as we want to do here, create a new event:
First, click the button labeled New. Splunk will display the Add New page:
Let's name our event type login.
We can now search for the same events using the event type:
Event types can be used as part of another search, as follows:
Event type definitions can also refer to other event...