I set up splunk light and configured remote windows eventlog monitoring. Then I started reading about the Universal forwarders. Now I want to switch everything over to the UF but the ones I have set up are now listed twice as search hosts. How do I remove the wmi data collectors?
hi bpeer,
placing here to close the question
you can try to go to settings (top right) -> data inputs -> Remote Events Log Collection -> look for your WMI inputs. -> disable or delete
hope it helps
hi bpeer,
placing here to close the question
you can try to go to settings (top right) -> data inputs -> Remote Events Log Collection -> look for your WMI inputs. -> disable or delete
hope it helps
That is what I was looking for. Thank you adonio.
Brad
hi bpeer,
you can try to go to settings (top right) -> data inputs -> Remote Events Log Collection -> look for your WMI inputs. -> disable or delete
hope it helps