Splunk IT Service Intelligence (ITSI) version 4.11.x will reach its End of Life on December 6, 2023. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see Before you upgrade IT Service Intelligence.
This documentation does not apply to the most recent version of Splunk® IT Service Intelligence. Click here for the latest version.Download topic as PDF
The following are the spec and example files for
# This file contains possible attribute/value pairs for blacklisting # notable event fields from the Common Fields section of episodes. # # There is a notable_event_commonality.conf in $SPLUNK_HOME/etc/apps/SA-ITOA/default/. # To set custom configurations, place a notable_event_commonality.conf in # $SPLUNK_HOME/etc/apps/SA-ITOA/local. You must restart Splunk software to enable # configurations. # # To learn more about configuration files (including precedence) please see # the documentation located at # http://docs.splunk.com/Documentation/ITSI/latest/Configure/ListofITSIconfigurationfiles
black_list_fields = <comma-separated list> * A list of field names in a notable event that will not appear in the Common Fields section of an episode. * By default, ITSI blacklists fields that are not core to the raw event itself, or ones that are mainly used internally. * Add fields here that you don't necessarily care about, but that you know will probably appear in most of your events.
Last modified on 16 September, 2021
This documentation applies to the following versions of Splunk® IT Service Intelligence: 4.11.0, 4.11.1, 4.11.2, 4.11.3, 4.11.4
Feedback submitted, thanks!