<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: eventtype BUG in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/eventtype-BUG/m-p/189265#M1723</link>
    <description>&lt;P&gt;Via an colleague of mine we did get it under the attention of Splunk Support and they where able to reproduce it and gave it a bug number: SPL-104263 &lt;/P&gt;</description>
    <pubDate>Tue, 21 Jul 2015 07:49:20 GMT</pubDate>
    <dc:creator>aholzel</dc:creator>
    <dc:date>2015-07-21T07:49:20Z</dc:date>
    <item>
      <title>eventtype BUG</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/eventtype-BUG/m-p/189263#M1721</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Because I am not able to file a bug report via the "File a bug" link that is present in Splunk (I get a Salesforce error) I post it here in the hope that someone from Splunk can pick it up.&lt;/P&gt;

&lt;P&gt;I believe I have found a bug in Splunk in eventtypes you can create via the GUI&lt;BR /&gt;
Steps to reproduce:&lt;BR /&gt;
 - Go to Settings &amp;gt; Event types&lt;BR /&gt;
 - Create a New eventtype&lt;BR /&gt;
 - Give it a name with a &lt;STRONG&gt;space&lt;/STRONG&gt; in it (the space is important because that is the trigger)&lt;BR /&gt;
 - Assign tags to it (also important to do because the tags are affected) &lt;BR /&gt;
 - Save (So far so good)&lt;BR /&gt;
 - Change the permissions van private to global&lt;/P&gt;

&lt;P&gt;Once you change the permissions the tags are "gone" the tags are not moved to the "global" tags.conf file. If you do the above for a eventtype that does not have a space in the name the tags are moved to the "global" tags.conf file. &lt;BR /&gt;
I think the problem is in the fact that in the eventtypes.conf file the stanza is creates as [test eventtype] ware as in the tags.conf the stanza is created as [eventtype=test%20eventtype] so the check to see if there are tags for an eventtype (or eventtypes for tags) fails.&lt;/P&gt;

&lt;P&gt;So also if you change the permissions van global to private again the tags remain in the "global" tags.conf file.&lt;/P&gt;

&lt;P&gt;Edit: I tested this in 6.2.2 and in 6.2.3&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 12:19:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/eventtype-BUG/m-p/189263#M1721</guid>
      <dc:creator>aholzel</dc:creator>
      <dc:date>2015-07-02T12:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: eventtype BUG</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/eventtype-BUG/m-p/189264#M1722</link>
      <description>&lt;P&gt;Not really an answer, but if you've found a bug the best thing to do is file a support case.  While someone who can deal with the bug may see this post, it's far more likely it will get triaged correctly if there's a support case.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 16:33:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/eventtype-BUG/m-p/189264#M1722</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2015-07-02T16:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: eventtype BUG</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/eventtype-BUG/m-p/189265#M1723</link>
      <description>&lt;P&gt;Via an colleague of mine we did get it under the attention of Splunk Support and they where able to reproduce it and gave it a bug number: SPL-104263 &lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2015 07:49:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/eventtype-BUG/m-p/189265#M1723</guid>
      <dc:creator>aholzel</dc:creator>
      <dc:date>2015-07-21T07:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: eventtype BUG</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/eventtype-BUG/m-p/189266#M1724</link>
      <description>&lt;P&gt;The first part of the original post explains why he/she couldn't open a support case.  I get the same error, namely when I click on "file a case", I get redirected to some odd error page telling me that my SSO cert failed, and I need to contact my salesforce.com administrator.&lt;/P&gt;

&lt;P&gt;Is there a workaround for that error?  I am trying to open a case (unrelated to the original poster's case)&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2015 20:12:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/eventtype-BUG/m-p/189266#M1724</guid>
      <dc:creator>grinabms</dc:creator>
      <dc:date>2015-09-23T20:12:36Z</dc:date>
    </item>
  </channel>
</rss>

