Getting Data In

How to remove the inputs that are given at time of universal forwarder installation

splunker_123
Path Finder

Hi

I've installed the splunk indexer on linux machine and universal forwader on a windows machine.While installing universal forwader - at the Installation wizard I gave some basic inputs to enable like CPU load,disk space and system log in windows but I dont want to monitor this any more so I need to remove this info.I have cleared the inputs.conf under $SPLUNKHOME/etc/apps/MSICreated/inputs.conf and $SPLUNKHOME/etc/system/local/inputs.conf but still the inputs ' CPU load,disk space and system log' is shown in splunk web console

How do I remove the above inputs from indexing please?

Thanks

0 Karma

jfraiberg
Communicator

etc/system/apps/unix/local

0 Karma

jfraiberg
Communicator

i am sorry, I misread your question. disregard my answer.

0 Karma

splunker_123
Path Finder

where this path will be please?
I can't find it in universal forwarder(windows) or in indexer

the only local folder is /etc/system/local and /etc/apps/MSICreated/local

0 Karma

splunker_123
Path Finder

Do any one have any clue on this please?

0 Karma

mikelanghorst
Motivator

run:
splunk cmd btool inputs list --debug

This will give you all of the configured inputs, and their properties. the first column will indicate which app has configured that input.

Is the data you're seeing possibly from before the inputs were removed? Did you restart after modifying the inputs?

0 Karma

splunker_123
Path Finder

there is nothing configured in the etc/system/local/inputs.conf but I can see few entries in etc/system/default/inputs.conf - is it taking input from there?
I can confirm it is the new data being indexed,not the old one because even after deleting the old data from index I can see the updated data again..

0 Karma

mikelanghorst
Motivator

This should be simple to fix, if you're interested and could join #splunk on EFNet we could knock this out pretty easy. http://cbe002.chat.mibbit.com/ is one webclient

0 Karma

mikelanghorst
Motivator

Would need to see you're etc/system/local/inputs.conf if it's not configured in there, then there's no reason why it should be still getting data if you've restarted. Can you confirm that new data is still being indexed, not just seeing old data?

0 Karma

splunker_123
Path Finder

anyone know this please?

0 Karma

splunker_123
Path Finder

I executed the above command and in the outputs listed I can't see the 'CPU load,disk space and system log'.the first column displays only one app - system.
yes I restarted twice after removing the inputs.conf

any other suggestions please?

0 Karma
Get Updates on the Splunk Community!

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...