I've created a dashboard in SideView that utilizes primarily datamodel searches. There is one search on raw events. I have created a number of event types for those raw events to get them to flow into the data models.
A couple of those event types were deleted months ago. When I add a search on raw events to the dashboard that would have been captured by those deleted event types, I see a warning at the top:
Eventtype 'Auditd -- New File Created' does not exist or is disabled.
Eventtype 'Auditd -- File Modified' does not exist or is disabled.
Using the same raw event search on a native Splunk dashboard doesn't throw any errors.
What do I have to do to make these errors go away, Nick?