<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it possible to prevent a system admin adding inputs at a forwarder? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-to-prevent-a-system-admin-adding-inputs-at-a/m-p/584113#M11511</link>
    <description>&lt;P&gt;Is it possible to prevent a system admin adding inputs at a forwarder? I only want sanctioned inputs to be used i.e. I want our Splunk admins to approve all forwarders and inputs. I thought deployment server might solve this but it does not cover all local inputs per say.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Mar 2022 16:59:05 GMT</pubDate>
    <dc:creator>shocko</dc:creator>
    <dc:date>2022-03-14T16:59:05Z</dc:date>
    <item>
      <title>Is it possible to prevent a system admin adding inputs at a forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-to-prevent-a-system-admin-adding-inputs-at-a/m-p/584113#M11511</link>
      <description>&lt;P&gt;Is it possible to prevent a system admin adding inputs at a forwarder? I only want sanctioned inputs to be used i.e. I want our Splunk admins to approve all forwarders and inputs. I thought deployment server might solve this but it does not cover all local inputs per say.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 16:59:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-to-prevent-a-system-admin-adding-inputs-at-a/m-p/584113#M11511</guid>
      <dc:creator>shocko</dc:creator>
      <dc:date>2022-03-14T16:59:05Z</dc:date>
    </item>
  </channel>
</rss>

