<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk IT Service Intelligence: Are notable event aggregation policies stored in a .conf file? in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/Splunk-IT-Service-Intelligence-Are-notable-event-aggregation/m-p/257947#M189</link>
    <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;ITSI Notable Event Aggregation Polices are stored in the KVStore. Collection related stanza is [itsi_notable_event_aggregation_policy] in&lt;BR /&gt;
SPLUNK_HOME/etc/apps/SA-ITOA/default/collections.conf.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 12:31:32 GMT</pubDate>
    <dc:creator>mglauser_splunk</dc:creator>
    <dc:date>2020-09-29T12:31:32Z</dc:date>
    <item>
      <title>Splunk IT Service Intelligence: Are notable event aggregation policies stored in a .conf file?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Splunk-IT-Service-Intelligence-Are-notable-event-aggregation/m-p/257946#M188</link>
      <description>&lt;P&gt;Are Splunk IT Service Intelligence (ITSI) notable event aggregation policies stored in a .conf file? If so, where is it?  the only thing that I see documented is how to view via the GUI.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 19:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Splunk-IT-Service-Intelligence-Are-notable-event-aggregation/m-p/257946#M188</guid>
      <dc:creator>earlhelms</dc:creator>
      <dc:date>2017-01-23T19:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk IT Service Intelligence: Are notable event aggregation policies stored in a .conf file?</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Splunk-IT-Service-Intelligence-Are-notable-event-aggregation/m-p/257947#M189</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;ITSI Notable Event Aggregation Polices are stored in the KVStore. Collection related stanza is [itsi_notable_event_aggregation_policy] in&lt;BR /&gt;
SPLUNK_HOME/etc/apps/SA-ITOA/default/collections.conf.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Splunk-IT-Service-Intelligence-Are-notable-event-aggregation/m-p/257947#M189</guid>
      <dc:creator>mglauser_splunk</dc:creator>
      <dc:date>2020-09-29T12:31:32Z</dc:date>
    </item>
  </channel>
</rss>

