Are Splunk IT Service Intelligence (ITSI) notable event aggregation policies stored in a .conf file? If so, where is it? the only thing that I see documented is how to view via the GUI.
Hello,
ITSI Notable Event Aggregation Polices are stored in the KVStore. Collection related stanza is [itsi_notable_event_aggregation_policy] in
SPLUNK_HOME/etc/apps/SA-ITOA/default/collections.conf.
Hello,
ITSI Notable Event Aggregation Polices are stored in the KVStore. Collection related stanza is [itsi_notable_event_aggregation_policy] in
SPLUNK_HOME/etc/apps/SA-ITOA/default/collections.conf.