This app was originally installed to forward all Win Evernt Logs to my Splunk server. I want to change this. Do I have to reinstall the software or is there a .conf file that I can update.
Thanks
look for the inputs.conf and wmi.conf etc... in the local folders.
and add disabled=true
see in $SPLUNK_HOME\etc\app\
and $SPLUNK_HOME\etc\system\local
for details : http://docs.splunk.com/Documentation/Splunk/5.0.1/admin/Inputsconf