<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After removing a monitor on one log file from all my Splunk forwarders, why do I still see search results for that log file? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/After-removing-a-monitor-on-one-log-file-from-all-my-Splunk/m-p/234049#M45606</link>
    <description>&lt;P&gt;Output of the command is not listing the removed files.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Oct 2016 23:27:16 GMT</pubDate>
    <dc:creator>smanda</dc:creator>
    <dc:date>2016-10-05T23:27:16Z</dc:date>
    <item>
      <title>After removing a monitor on one log file from all my Splunk forwarders, why do I still see search results for that log file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-removing-a-monitor-on-one-log-file-from-all-my-Splunk/m-p/234047#M45604</link>
      <description>&lt;P&gt;I removed a monitor on one log file from all the Splunk forwarders in the inputs.conf file and restarted Splunk forwarder and Splunk indexers. However, we still see the new logs been indexed and search results returned.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 19:35:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-removing-a-monitor-on-one-log-file-from-all-my-Splunk/m-p/234047#M45604</guid>
      <dc:creator>smanda</dc:creator>
      <dc:date>2016-10-05T19:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: After removing a monitor on one log file from all my Splunk forwarders, why do I still see search results for that log file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-removing-a-monitor-on-one-log-file-from-all-my-Splunk/m-p/234048#M45605</link>
      <description>&lt;P&gt;What is the &lt;CODE&gt;btool&lt;/CODE&gt; telling on the forwarders?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; ./splunk cmd btool inputs list monitor
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is it listing the &lt;STRONG&gt;removed&lt;/STRONG&gt; files?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 22:32:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-removing-a-monitor-on-one-log-file-from-all-my-Splunk/m-p/234048#M45605</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-10-05T22:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: After removing a monitor on one log file from all my Splunk forwarders, why do I still see search results for that log file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-removing-a-monitor-on-one-log-file-from-all-my-Splunk/m-p/234049#M45606</link>
      <description>&lt;P&gt;Output of the command is not listing the removed files.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 23:27:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-removing-a-monitor-on-one-log-file-from-all-my-Splunk/m-p/234049#M45606</guid>
      <dc:creator>smanda</dc:creator>
      <dc:date>2016-10-05T23:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: After removing a monitor on one log file from all my Splunk forwarders, why do I still see search results for that log file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-removing-a-monitor-on-one-log-file-from-all-my-Splunk/m-p/234050#M45607</link>
      <description>&lt;P&gt;And you see fresh data from this particular host on which you ran the &lt;CODE&gt;btool&lt;/CODE&gt; command, right? Doesn't make any sense.&lt;/P&gt;

&lt;P&gt;Anybody has any idea?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2016 15:41:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-removing-a-monitor-on-one-log-file-from-all-my-Splunk/m-p/234050#M45607</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-10-06T15:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: After removing a monitor on one log file from all my Splunk forwarders, why do I still see search results for that log file?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-removing-a-monitor-on-one-log-file-from-all-my-Splunk/m-p/234051#M45608</link>
      <description>&lt;P&gt;Yes. Its showing the monitors which we configured in inputs.conf right now.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2016 17:13:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-removing-a-monitor-on-one-log-file-from-all-my-Splunk/m-p/234051#M45608</guid>
      <dc:creator>smanda</dc:creator>
      <dc:date>2016-10-06T17:13:16Z</dc:date>
    </item>
  </channel>
</rss>

