Knowledge Management

Web Intelligence: local/eventtypes.conf will not override default/eventtypes.conf

oscarspaz
Explorer

I was trying the use ./local/eventtypes.conf to override the values in ./default/eventtypes.conf.
Using btool, it shows that local eventtype was picked. However, in Splunk web Manager->Event Type, it shows the default values instead of local values. Therefore, Web Intelligence App failed to assigned the correct eventtypes to incoming logs.

Does anyone has the same problem? How do you fix it?

0 Karma

oscarspaz
Explorer

I followed the instructions and use the Setup workflow and get no results. I managed to get it working by editing the default/eventtypes.conf.

I documented my discoveries in this post

http://splunk-base.splunk.com/answers/34974/no-results-found-using-web-intelligence-app

I am beginning to wonder if it is a problem for Windows only.

0 Karma

araitz
Splunk Employee
Splunk Employee

A more primary question: why aren't you using the apps' own Setup workflow?

dwaddle
SplunkTrust
SplunkTrust

Potentially dumb question, but local/eventtypes.conf versus local/eventtype.conf? Is this merely a typo?

oscarspaz
Explorer

Thank for pointing that out. It was a typo. I updated the post.

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...