Getting Data In

inputs.conf

splunker_123
Path Finder

Hi

I've few indexing issues here,I have three to five entries in the inputs.conf of a universal forwader in a windows machine and my splunk indexer is in linux machine so now the forwarders is forwarding the data to indexer but later I thought of removing the existing entries in inputs.conf and add different input there however when I look into the splunkweb console I can still see the my old logs(the log location which I gave in inputs.conf at first) along with new log files.I thought if we delete the log location(input) from inputs.conf splunk will stop indexing and will not be shown in splunk web console?

Tags (1)
0 Karma

Drainy
Champion

If you make any changes to inputs.conf then you need to restart splunk to accept the changes. Any changes made to inputs via the web GUI will take effect immediately.
Any logs which have already been consumed from that input will not be removed from your Splunk indexes but will remain, you simply won't have any more data added to those sources/sourcetypes.

If you wanted to hide this data so it doesn't show then have a look here;
http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/RemovedatafromSplunk

If you are just using the one index then it isn't really feasible to properly delete and reclaim the used disc space from that input, but it will eventually roll out depending on your retention policies.

mikelanghorst
Motivator

When you're searching you're still seeing current data from the old location, or are you simply saying that you can still search for the old location?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...