Documentation: 3.3
Print Version Contents
This page last updated: 08/26/08 02:08pm

eventdiscoverer.conf

eventdiscover.conf controls whether and how Splunk attempts to automatically learn new event types.

eventdiscoverer.conf.spec

# Copyright (C) 2005-2008 Splunk Inc.  All Rights Reserved.  Version 3.0 

# This file contains possible attributes and values you can use to configure event discovery through
# the search command "typelearner."
#
# There is an eventdiscoverer.conf in $SPLUNK_HOME/etc/system/default/.  To set custom configurations, 
# place an eventdiscoverer.conf in $SPLUNK_HOME/etc/system/local/.  For examples, see 
# eventdiscoverer.conf.example. You must restart Splunk to enable configurations.
#
# To learn more about configuration files (including precedence) please see the documentation 
# located at http://www.splunk.com/doc/latest/admin/BundlesIntro.

ignored_keywords = <comma-separated list of terms> 
        * Terms in this list are never considered for defining an event type.  
        * If you find that eventtypes have terms you do not want considered (e.g., "mylaptopname"), add
        that term to this list.
        * Default = "sun, mon, tue,..." (see $SPLUNK_HOME/etc/system/default/eventdiscover.conf).

ignored_fields = <comma-separated list of fields>
        * Similar to ignored_keywords, except fields as defined in Splunk.
        * Defaults include time-related fields that would not be useful for defining an event type.

eventdiscoverer.conf.example

# Copyright (C) 2005-2008 Splunk Inc.  All Rights Reserved.  Version 3.0 
#
# This is an example eventdiscoverer.conf.  These settings are used to control the discovery of 
# common eventtypes used by the typelearner search command.
#
# To use one or more of these configurations, copy the configuration block into eventdiscoverer.conf 
# in $SPLUNK_HOME/etc/system/local/.  You must restart Splunk to enable configurations.
#
# To learn more about configuration files (including precedence) please see the documentation 
# located at http://www.splunk.com/doc/latest/admin/BundlesIntro.

# Terms in this list are never considered for defining an eventtype.
ignored_keywords = foo, bar, application, kate, charlie

# Fields in this list are never considered for defining an eventtype.
ignored_fields = pid, others, directory
Previous: distsearch.conf    |    Next: eventtypes.conf

Comments

No comments have been submitted.

Log in to comment.