Getting Data In

Perfmon sending logs to the wrong indexer

splunktrainingu
Communicator

I have a single instance deployment. I have a server that is sending Perfmon logs to my main index but I never told it to send those logs. Where do I check those settings? I want to keep it sending logs but to the correct index. So I made a perfmon index but I cannot find where on the server this configuration files is. I checked etc/system/local couldn't find anything.

Labels (1)
Tags (1)
0 Karma
1 Solution

splunktrainingu
Communicator

I was able to find that there was an application called Splunk TA (splunkuniversalforwarder/etc/apps) which resided on that machine simply deleted it because I know I do not have this on my fresh install of Splunk so it won't be pushed out again also checked my deployment server and made sure it is none existent there.

View solution in original post

0 Karma

splunktrainingu
Communicator

I was able to find that there was an application called Splunk TA (splunkuniversalforwarder/etc/apps) which resided on that machine simply deleted it because I know I do not have this on my fresh install of Splunk so it won't be pushed out again also checked my deployment server and made sure it is none existent there.

0 Karma
Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...