Knowledge Management

Web Intelligence: local/eventtypes.conf will not override default/eventtypes.conf

oscarspaz
Explorer

I was trying the use ./local/eventtypes.conf to override the values in ./default/eventtypes.conf.
Using btool, it shows that local eventtype was picked. However, in Splunk web Manager->Event Type, it shows the default values instead of local values. Therefore, Web Intelligence App failed to assigned the correct eventtypes to incoming logs.

Does anyone has the same problem? How do you fix it?

0 Karma

oscarspaz
Explorer

I followed the instructions and use the Setup workflow and get no results. I managed to get it working by editing the default/eventtypes.conf.

I documented my discoveries in this post

http://splunk-base.splunk.com/answers/34974/no-results-found-using-web-intelligence-app

I am beginning to wonder if it is a problem for Windows only.

0 Karma

araitz
Splunk Employee
Splunk Employee

A more primary question: why aren't you using the apps' own Setup workflow?

dwaddle
SplunkTrust
SplunkTrust

Potentially dumb question, but local/eventtypes.conf versus local/eventtype.conf? Is this merely a typo?

oscarspaz
Explorer

Thank for pointing that out. It was a typo. I updated the post.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...