Knowledge Management

eventtypes - disabled 1 or 0

MikeyG
Explorer

V4.2.3 - eventtypes not showing up after recent upgrade ...

There is this reference:
http://docs.splunk.com/Documentation/Splunk/4.2.3/Knowledge/Configureeventtypes

and then there is this:
http://docs.splunk.com/Documentation/Splunk/4.2.3/Admin/Eventtypesconf

Boolean logic aside, which is disabled 1 or 0 ??

Tags (2)
0 Karma

gekoner
Communicator

Considering everything else in Splunk configuration files is disabled = 1, I'd go with that if you WANT TO DISABLE EventLogging.
You could always use disabled = true/false

Just to reiterate
true = 1
false= 0

crazydave
New Member

Skimming through docs and help I cannot see any clear statement that you can use true or false in place of 1 and 0.
Do you know if we can safely use 'true' / 'false' in all cases where '0' or '1' is in the examples/docs?
I'm guessing I'll see a parsing error on start up of the forwarder if 'true' or 'false' is not accepted in place of '0' or '1' ... not seen one yet.
Ta. David.

0 Karma
Get Updates on the Splunk Community!

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...

Video | Welcome Back to Smartness, Pedro

Remember Splunk Community member, Pedro Borges? If you tuned into Episode 2 of our Smartness interview series, ...

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...