<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to disable logging in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/568733#M100913</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for your reply, I didn't see your question.&lt;/P&gt;&lt;P&gt;We recieve application logs from several forwarders. We have a clustered environment with 1 Master server and 3 indexers.&lt;/P&gt;&lt;P&gt;See attached screenshot for the 3 indexers that appear within "Forward Data". Our "Receive Data" link is blank.&lt;/P&gt;&lt;P&gt;Which sub page should I be going into to make the changes to disable log forwarding/receiving? I'm unclear if I should be disabling forwarding or receiving at this point.&lt;/P&gt;&lt;P&gt;Thanks for your patience.&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;</description>
    <pubDate>Tue, 28 Sep 2021 14:01:17 GMT</pubDate>
    <dc:creator>Jnewman28</dc:creator>
    <dc:date>2021-09-28T14:01:17Z</dc:date>
    <item>
      <title>How to disable logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/567848#M100820</link>
      <description>&lt;P&gt;We are currently running Splunk Enterprise, on-prem on a Linux VM and have a search head, with several forwarders.&lt;/P&gt;&lt;P&gt;How can we maintain the search functionality for historical log data, but stop/disable logging of any new data, either a blanket stop for all hosts/forwarders, or individually?&lt;/P&gt;&lt;P&gt;I think this can be done in the .conf file somehow? Is there an easier way to do this?&lt;/P&gt;&lt;P&gt;Our Splunk System Admin has left our company and I am trying to get up to speed on how this would be done.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 14:42:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/567848#M100820</guid>
      <dc:creator>Jnewman28</dc:creator>
      <dc:date>2021-09-21T14:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/567850#M100821</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233612"&gt;@Jnewman28&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to disable the Receiving from all the Forwarders [Settings -- Forwarding and Receiving -- Receiving].&lt;/P&gt;&lt;P&gt;Then, if you have other inputs on the Indexers (network, HEC, WMI, etc...), you have to disable them one by one.&lt;/P&gt;&lt;P&gt;In this way you'll be able to search all the events from the retention date to the block date until you'll have a Splunk license.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 14:51:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/567850#M100821</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-09-21T14:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/567866#M100822</link>
      <description>&lt;P&gt;Thanks for the reply. If we eventually downgraded to the free license sometime in the future, would that prevent us in any way from accessing the historical log data through searching in the Splunk UI?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 15:38:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/567866#M100822</guid>
      <dc:creator>Jnewman28</dc:creator>
      <dc:date>2021-09-21T15:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/567870#M100823</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233612"&gt;@Jnewman28&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;ablolutely not: with the Free license you'll be able to access all the data you have, but with limited function (e.g. you will not have the login).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 15:49:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/567870#M100823</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-09-21T15:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/568045#M100832</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;Thank you. When I went to this page, there are no configurations listed.&lt;/P&gt;&lt;P&gt;When I click "New", it asks &lt;EM&gt;"Listen on this port&amp;nbsp;&lt;SPAN class="requiredAsterisk"&gt;*"&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="requiredAsterisk"&gt;What information needs to be entered to disable receiving? I was hoping there would be a simple On/Off receive function. I want to know how to do this end to end, but not actually perform this now.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="requiredAsterisk"&gt;Thanks for your input for a Splunk newbie.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="lia-message-author-with-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 22 Sep 2021 13:53:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/568045#M100832</guid>
      <dc:creator>Jnewman28</dc:creator>
      <dc:date>2021-09-22T13:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/568048#M100833</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233612"&gt;@Jnewman28&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;one step back:&lt;/P&gt;&lt;P&gt;which kind of logs are you receiving?&lt;/P&gt;&lt;P&gt;If you have forwarders that send logs to the Indexers, you have to disable receiving in all &lt;STRONG&gt;indexers&lt;/STRONG&gt;&amp;nbsp;following the procedure I described.&lt;/P&gt;&lt;P&gt;So if you don't find any receiving configurations, maybe you're watching in the wrong server, are they Indexers?&lt;/P&gt;&lt;P&gt;If you have other kinds of logs you have to disable them one by one always on Indexers.&lt;/P&gt;&lt;P&gt;In other words, have a you a perimeter that maps your data flows?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 13:58:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/568048#M100833</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-09-22T13:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/568733#M100913</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for your reply, I didn't see your question.&lt;/P&gt;&lt;P&gt;We recieve application logs from several forwarders. We have a clustered environment with 1 Master server and 3 indexers.&lt;/P&gt;&lt;P&gt;See attached screenshot for the 3 indexers that appear within "Forward Data". Our "Receive Data" link is blank.&lt;/P&gt;&lt;P&gt;Which sub page should I be going into to make the changes to disable log forwarding/receiving? I'm unclear if I should be disabling forwarding or receiving at this point.&lt;/P&gt;&lt;P&gt;Thanks for your patience.&lt;/P&gt;&lt;P&gt;Jacob&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 14:01:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/568733#M100913</guid>
      <dc:creator>Jnewman28</dc:creator>
      <dc:date>2021-09-28T14:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/568735#M100914</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233612"&gt;@Jnewman28&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;No problem, it's a pleasure to help you.&lt;/P&gt;&lt;P&gt;To receive logs from forwarders, you should have enabled receiving [Settings - Forwarding and receiving -- Receiving] in all your 3 Indexers, something like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gcusello_0-1632837941423.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16188i2C11F0F5967823AA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="gcusello_0-1632837941423.png" alt="gcusello_0-1632837941423.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And you have to disable it to stop Forwarders' logs without stopping each Forwarder, otherwise you have to stop each Forwarder.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 14:09:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/568735#M100914</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-09-28T14:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/572668#M101336</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I look at my Master server, as well as the individual server, within Settings &amp;gt; Forwarding and Receiving &amp;gt; Receiving, nothing is listed. It's blank.&lt;/P&gt;&lt;P&gt;However, within the Master server, under Forwarding, I see the forwarding to our 3 servers, see image below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jnewman28_0-1635346131167.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16611iCC97191695BD89ED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jnewman28_0-1635346131167.png" alt="Jnewman28_0-1635346131167.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I navigate to Receiving, it's blank, as seen below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jnewman28_1-1635346233871.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16612i289684F2E34B57ED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Jnewman28_1-1635346233871.png" alt="Jnewman28_1-1635346233871.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How would I disable receiving then, within the indexers themselves?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 14:51:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/572668#M101336</guid>
      <dc:creator>Jnewman28</dc:creator>
      <dc:date>2021-10-27T14:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/572670#M101337</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233612"&gt;@Jnewman28&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;have you an Indexer Cluster or a stand-alone server?&lt;/P&gt;&lt;P&gt;Viewing your screenshot I see that you're in the Master Node, infact it sends its internal logs to the three Indexers you have (splunk-idx-c1.hfelocal.corp, etc...) but it hasn't an active receiving because Master Node doesn't receive logs.&lt;/P&gt;&lt;P&gt;You have to disable receiving in your Indexers, not in Master Node.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 15:01:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/572670#M101337</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-10-27T15:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/572673#M101339</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your quick reply.&lt;/P&gt;&lt;P&gt;Where can I locate my indexers so I can disable receiving within them?&lt;/P&gt;&lt;P&gt;Is disabling within the indexers done in the Splunk UI?&lt;/P&gt;&lt;P&gt;I really appreciate your help.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 15:15:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/572673#M101339</guid>
      <dc:creator>Jnewman28</dc:creator>
      <dc:date>2021-10-27T15:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/572676#M101340</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;here is good instructions how to figure out what you have in your splunk installations&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/InheritedDeployment/Introduction" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/InheritedDeployment/Introduction&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 15:23:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/572676#M101340</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-10-27T15:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable logging</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/572677#M101341</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233612"&gt;@Jnewman28&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You should be able to access via GUI to your Indexers.&lt;/P&gt;&lt;P&gt;You can find the Receiving configuration at&amp;nbsp;&lt;SPAN&gt;[Settings -- Forwarding and Receiving -- Receiving].&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You indexers are called&amp;nbsp;splunk-idx-c1.hfelocal.corp,&amp;nbsp;splunk-idx-c2.hfelocal.corp,&amp;nbsp;splunk-idx-c3.hfelocal.corp.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 15:24:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-disable-logging/m-p/572677#M101341</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-10-27T15:24:22Z</dc:date>
    </item>
  </channel>
</rss>

