All Apps and Add-ons

How to make the errors go away in SideView dashboard?


I've created a dashboard in SideView that utilizes primarily datamodel searches. There is one search on raw events. I have created a number of event types for those raw events to get them to flow into the data models.

A couple of those event types were deleted months ago. When I add a search on raw events to the dashboard that would have been captured by those deleted event types, I see a warning at the top:

Eventtype 'Auditd -- New File Created' does not exist or is disabled.
Eventtype 'Auditd -- File Modified' does not exist or is disabled.

Using the same raw event search on a native Splunk dashboard doesn't throw any errors.

What do I have to do to make these errors go away, Nick?



0 Karma


could you please provide your query

0 Karma
Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...