Getting Data In

Universal forwarder on Windows to monitor a single folder, nothing else

bvoros
New Member

Hello All,

I want to set up the universal forwarder on a Windows machine to monitor a single folder without it sending event logs and any other data.

I have just set it up, only entered the folder I want to be monitored but it still sends in heaps of event logs and other stuff I dont want to collect.
How do I turn that off?

So again only the monitored folder, nothing else.

Thanks and best regards,
Bertalan

Tags (1)
0 Karma

yannK
Splunk Employee
Splunk Employee

Just purged the unwanted data out of the index, it was stuff collected by the mandatory Windows Technology add on despite not having checked any of the check boxes

Yes, this is happening during the splunk6 install, and the app comes with inputs enabled by default 😞
A solution is to delete the windows TA app from $SPLUNK_HOME\etc\apps\, and restart splunk.

0 Karma

bvoros
New Member

The quick fix is using version 5.

0 Karma

bvoros
New Member

Just purged the unwanted data out of the index, it was stuff collected by the mandatory Windows Technology add on despite not having checked any of the check boxes.

I am using Splunk 6.

0 Karma

lukejadamec
Super Champion

Can you list the sourcetypes of data coming from the host?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...