Getting Data In

How to remove the inputs that are given at time of universal forwarder installation

splunker_123
Path Finder

Hi

I've installed the splunk indexer on linux machine and universal forwader on a windows machine.While installing universal forwader - at the Installation wizard I gave some basic inputs to enable like CPU load,disk space and system log in windows but I dont want to monitor this any more so I need to remove this info.I have cleared the inputs.conf under $SPLUNKHOME/etc/apps/MSICreated/inputs.conf and $SPLUNKHOME/etc/system/local/inputs.conf but still the inputs ' CPU load,disk space and system log' is shown in splunk web console

How do I remove the above inputs from indexing please?

Thanks

0 Karma

jfraiberg
Communicator

etc/system/apps/unix/local

0 Karma

jfraiberg
Communicator

i am sorry, I misread your question. disregard my answer.

0 Karma

splunker_123
Path Finder

where this path will be please?
I can't find it in universal forwarder(windows) or in indexer

the only local folder is /etc/system/local and /etc/apps/MSICreated/local

0 Karma

splunker_123
Path Finder

Do any one have any clue on this please?

0 Karma

mikelanghorst
Motivator

run:
splunk cmd btool inputs list --debug

This will give you all of the configured inputs, and their properties. the first column will indicate which app has configured that input.

Is the data you're seeing possibly from before the inputs were removed? Did you restart after modifying the inputs?

0 Karma

splunker_123
Path Finder

there is nothing configured in the etc/system/local/inputs.conf but I can see few entries in etc/system/default/inputs.conf - is it taking input from there?
I can confirm it is the new data being indexed,not the old one because even after deleting the old data from index I can see the updated data again..

0 Karma

mikelanghorst
Motivator

This should be simple to fix, if you're interested and could join #splunk on EFNet we could knock this out pretty easy. http://cbe002.chat.mibbit.com/ is one webclient

0 Karma

mikelanghorst
Motivator

Would need to see you're etc/system/local/inputs.conf if it's not configured in there, then there's no reason why it should be still getting data if you've restarted. Can you confirm that new data is still being indexed, not just seeing old data?

0 Karma

splunker_123
Path Finder

anyone know this please?

0 Karma

splunker_123
Path Finder

I executed the above command and in the outputs listed I can't see the 'CPU load,disk space and system log'.the first column displays only one app - system.
yes I restarted twice after removing the inputs.conf

any other suggestions please?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...