<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: disable splunk stream in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/disable-splunk-stream/m-p/540264#M4975</link>
    <description>&lt;P&gt;Within the Stream app &amp;lt; configuration &amp;lt; distributed forwarder management &amp;lt; There is a default group and MATCHED FORWARDERS but that link is not editable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Feb 2021 15:02:35 GMT</pubDate>
    <dc:creator>iherb_0718</dc:creator>
    <dc:date>2021-02-17T15:02:35Z</dc:date>
    <item>
      <title>disable splunk stream</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/disable-splunk-stream/m-p/540039#M4952</link>
      <description>&lt;P&gt;Anyone have the directions handy to disable splunk stream on a particular server? Is it done via the splunk stream app?&lt;/P&gt;&lt;P&gt;I want to disable it in a way that the service will not start up when the server reboots.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 03:42:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/disable-splunk-stream/m-p/540039#M4952</guid>
      <dc:creator>iherb_0718</dc:creator>
      <dc:date>2021-02-16T03:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: disable splunk stream</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/disable-splunk-stream/m-p/540090#M4963</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229889"&gt;@iherb_0718&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;How are you deploying the Splunk Stream app to your servers? Are you using a deployment server? If so, you could try removing your server from the server class that deploys this app. I guess this would uninstall the Splunk Stream app from the server.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 13:05:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/disable-splunk-stream/m-p/540090#M4963</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2021-02-16T13:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: disable splunk stream</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/disable-splunk-stream/m-p/540210#M4974</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229889"&gt;@iherb_0718&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can remove that particular server from Forwarder groups on Splunk Stream App | Distributed Forwarder Management.&lt;/P&gt;&lt;P&gt;Streamfwd service will start but not start listening.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 09:20:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/disable-splunk-stream/m-p/540210#M4974</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-17T09:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: disable splunk stream</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/disable-splunk-stream/m-p/540264#M4975</link>
      <description>&lt;P&gt;Within the Stream app &amp;lt; configuration &amp;lt; distributed forwarder management &amp;lt; There is a default group and MATCHED FORWARDERS but that link is not editable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 15:02:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/disable-splunk-stream/m-p/540264#M4975</guid>
      <dc:creator>iherb_0718</dc:creator>
      <dc:date>2021-02-17T15:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: disable splunk stream</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/disable-splunk-stream/m-p/540269#M4976</link>
      <description>&lt;P&gt;This is default group that catches forwarders if no other group matches.&lt;/P&gt;&lt;P&gt;You should create a new group and move your stream setups to new one. Setup match forwarders regex to match only your server that you want. This will be your active configuration point.&lt;/P&gt;&lt;P&gt;Default group should not contain any stream. Your unwanted server will be seen under this default group and does not listen any stream.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 15:47:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/disable-splunk-stream/m-p/540269#M4976</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-17T15:47:33Z</dc:date>
    </item>
  </channel>
</rss>

