Hi there,
is there a way to stop a Splunk Forwarder when its sending more then for instance 2 GB ?
From a SearchHead I could configure an alert which appear if a Forwarder logs more than 2 GB. But after appearing the alert, is there a way to stop the Splunk Forwarder deamon via REST API or start a other script which can stop the Forwarder via Port 8089 ?
The problem is I just can reach the known ports, I can not access via SSH to the Forwarders.
Thank you
Regards
Hi,
I solved the problem with using limits.conf (max troughput).
greetings
Hi,
I solved the problem with using limits.conf (max troughput).
greetings