Knowledge Management

Web Intelligence: local/eventtypes.conf will not override default/eventtypes.conf

oscarspaz
Explorer

I was trying the use ./local/eventtypes.conf to override the values in ./default/eventtypes.conf.
Using btool, it shows that local eventtype was picked. However, in Splunk web Manager->Event Type, it shows the default values instead of local values. Therefore, Web Intelligence App failed to assigned the correct eventtypes to incoming logs.

Does anyone has the same problem? How do you fix it?

0 Karma

oscarspaz
Explorer

I followed the instructions and use the Setup workflow and get no results. I managed to get it working by editing the default/eventtypes.conf.

I documented my discoveries in this post

http://splunk-base.splunk.com/answers/34974/no-results-found-using-web-intelligence-app

I am beginning to wonder if it is a problem for Windows only.

0 Karma

araitz
Splunk Employee
Splunk Employee

A more primary question: why aren't you using the apps' own Setup workflow?

dwaddle
SplunkTrust
SplunkTrust

Potentially dumb question, but local/eventtypes.conf versus local/eventtype.conf? Is this merely a typo?

oscarspaz
Explorer

Thank for pointing that out. It was a typo. I updated the post.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...