<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable the Universal Forwarder Clients in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Disable-the-Universal-Forwarder-Clients/m-p/197996#M39280</link>
    <description>&lt;P&gt;This stanza doesn't work, tried on UF 6.1.1 and Indexer 6.1.1&lt;/P&gt;

&lt;P&gt;data still coming to indexer after pushed out the app, checked is on the UF client  and restart the UF client but still getting data to the indexer&lt;/P&gt;

&lt;P&gt;And this only disabled a particular apps  in UF?  IU?&lt;/P&gt;

&lt;P&gt;i want to disable UF if it sending too much data or a least able to turn on/off as needed.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Jun 2014 18:44:55 GMT</pubDate>
    <dc:creator>tlow</dc:creator>
    <dc:date>2014-06-13T18:44:55Z</dc:date>
    <item>
      <title>Disable the Universal Forwarder Clients</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Disable-the-Universal-Forwarder-Clients/m-p/197994#M39278</link>
      <description>&lt;P&gt;what is the best ways to disable the universal Forwarder Clients sending data to the indexer.&lt;/P&gt;

&lt;P&gt;I tried deploying an apps with inputs.conf&lt;/P&gt;

&lt;P&gt;[default]&lt;BR /&gt;
disabled=1&lt;/P&gt;

&lt;P&gt;to disable all inputs, so there is no data sending the indexer.&lt;/P&gt;

&lt;P&gt;or could change the outputs.conf on the client using deployment server&lt;/P&gt;

&lt;P&gt;want to able to disable the UF clients.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2014 16:23:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Disable-the-Universal-Forwarder-Clients/m-p/197994#M39278</guid>
      <dc:creator>tlow</dc:creator>
      <dc:date>2014-06-13T16:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: Disable the Universal Forwarder Clients</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Disable-the-Universal-Forwarder-Clients/m-p/197995#M39279</link>
      <description>&lt;P&gt;I think the easiest way to do this will be to disable the apps on the forwarders. On the deployment server, edit &lt;STRONG&gt;app.conf&lt;/STRONG&gt; for each of the apps that are distributed to the UFs, adding the following&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[install]
state = disabled
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then reload the deployment server so it will distribute the updated/disabled app to all the forwarders.&lt;/P&gt;

&lt;P&gt;A disabled app is completely ignored, so this effectively disables all the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and &lt;CODE&gt;outputs.conf&lt;/CODE&gt; that are configured in apps. The only risk may be any UFs that have set inputs or outputs in &lt;CODE&gt;etc/system/local&lt;/CODE&gt; - hopefully there are none of those in your environment.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2014 16:53:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Disable-the-Universal-Forwarder-Clients/m-p/197995#M39279</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2014-06-13T16:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Disable the Universal Forwarder Clients</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Disable-the-Universal-Forwarder-Clients/m-p/197996#M39280</link>
      <description>&lt;P&gt;This stanza doesn't work, tried on UF 6.1.1 and Indexer 6.1.1&lt;/P&gt;

&lt;P&gt;data still coming to indexer after pushed out the app, checked is on the UF client  and restart the UF client but still getting data to the indexer&lt;/P&gt;

&lt;P&gt;And this only disabled a particular apps  in UF?  IU?&lt;/P&gt;

&lt;P&gt;i want to disable UF if it sending too much data or a least able to turn on/off as needed.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2014 18:44:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Disable-the-Universal-Forwarder-Clients/m-p/197996#M39280</guid>
      <dc:creator>tlow</dc:creator>
      <dc:date>2014-06-13T18:44:55Z</dc:date>
    </item>
  </channel>
</rss>

