Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

splunk tags.conf disable stanza

$
0
0
We need to override a tags & eventtypes from one of the official TA (eg `eventtype=ssh_authentication`). eventtypes.conf have `disabled=true` at a stanza level, but tags.conf does NOT have such ability as per spec. Any chance to disable entire stanza of tags.conf? What we are looking for is something like below in tags.conf [eventtype=ssh_authentication] disabled=true PS: If we don't do this, there is a "WARN" while doing Splunk search in GUI saying "unable to find eventtype=xxxxx".

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>