Knowledge Management

Web Intelligence: local/eventtypes.conf will not override default/eventtypes.conf

oscarspaz
Explorer

I was trying the use ./local/eventtypes.conf to override the values in ./default/eventtypes.conf.
Using btool, it shows that local eventtype was picked. However, in Splunk web Manager->Event Type, it shows the default values instead of local values. Therefore, Web Intelligence App failed to assigned the correct eventtypes to incoming logs.

Does anyone has the same problem? How do you fix it?

0 Karma

oscarspaz
Explorer

I followed the instructions and use the Setup workflow and get no results. I managed to get it working by editing the default/eventtypes.conf.

I documented my discoveries in this post

http://splunk-base.splunk.com/answers/34974/no-results-found-using-web-intelligence-app

I am beginning to wonder if it is a problem for Windows only.

0 Karma

araitz
Splunk Employee
Splunk Employee

A more primary question: why aren't you using the apps' own Setup workflow?

dwaddle
SplunkTrust
SplunkTrust

Potentially dumb question, but local/eventtypes.conf versus local/eventtype.conf? Is this merely a typo?

oscarspaz
Explorer

Thank for pointing that out. It was a typo. I updated the post.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...