Event annotations

An annotation is generally defined as an explanation or comment; event annotations are new in Splunk version 7.0. With the implementation of this feature, you can now add explanations or context to trends returned by Splunk (time) charts. Splunk event annotations are presented as colored flags that display time stamp information and custom descriptions in labels when you hover your mouse over them, as shown in the example in the following screenshot:

To illustrate how an event annotation could be used, Splunk offers an example where administrators are monitoring machine logs looking for user login errors. There is a Splunk ...

Get Improving Your Splunk Skills now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.