* **Event Types** group essentially identical events together using a saved Splunk search (e.g., `sourcetype=cisco:asa action=blocked` becomes `eventtype=firewall_block`).
* **Tags** apply keyword labels to specific field-value pairs (e.g., tagging `host=10.0.0.1` as `webserver`).
They can work together! You can even tag an Event Type.