<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fully disable perfmon in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495388#M84496</link>
    <description>&lt;P&gt;there shouldn't be any UF with the app installed no&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jan 2020 00:19:30 GMT</pubDate>
    <dc:creator>mavilla</dc:creator>
    <dc:date>2020-01-24T00:19:30Z</dc:date>
    <item>
      <title>Fully disable perfmon</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495386#M84494</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;

&lt;P&gt;I am trying to fully disable perfmon from our splunk instance as we don not use this data to monitor any of the hosts. I have disabled the setting in Splunk Web and have the data is still there when I run the query to search for perfmon data. I've read on older posts on how to disable this feature, however, I do not have the Splunk_TA for windows folder as I've never had the app to use the perfmon data. Any other guidance on how to fully disable this feature?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2020 00:13:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495386#M84494</guid>
      <dc:creator>mavilla</dc:creator>
      <dc:date>2020-01-24T00:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Fully disable perfmon</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495387#M84495</link>
      <description>&lt;P&gt;Are there UF that have the app installed? Also you might want to check SPLUNK_HOME/etc/system/local. If there is an inputs.conf with the stanza's in there.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2020 00:18:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495387#M84495</guid>
      <dc:creator>jscraig2006</dc:creator>
      <dc:date>2020-01-24T00:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Fully disable perfmon</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495388#M84496</link>
      <description>&lt;P&gt;there shouldn't be any UF with the app installed no&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2020 00:19:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495388#M84496</guid>
      <dc:creator>mavilla</dc:creator>
      <dc:date>2020-01-24T00:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: Fully disable perfmon</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495389#M84497</link>
      <description>&lt;P&gt;Sorry i edited my comment as you posted..  check SPLUNK_HOME/etc/system/local. If there is an inputs.conf with the stanza's in there&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2020 00:23:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495389#M84497</guid>
      <dc:creator>jscraig2006</dc:creator>
      <dc:date>2020-01-24T00:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: Fully disable perfmon</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495390#M84498</link>
      <description>&lt;P&gt;there is not a stanza for this in that file&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2020 00:25:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495390#M84498</guid>
      <dc:creator>mavilla</dc:creator>
      <dc:date>2020-01-24T00:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Fully disable perfmon</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495391#M84499</link>
      <description>&lt;P&gt;do you have the Splunk_TA_microsoft_ad app installed? Run this command on on of the universal forwarder that is sending the data. &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;.\splunk.exe cmd btool inputs list --debug&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:48:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495391#M84499</guid>
      <dc:creator>jscraig2006</dc:creator>
      <dc:date>2020-09-30T03:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: Fully disable perfmon</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495392#M84500</link>
      <description>&lt;P&gt;I do not have this app installed either&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2020 14:27:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Fully-disable-perfmon/m-p/495392#M84500</guid>
      <dc:creator>mavilla</dc:creator>
      <dc:date>2020-01-24T14:27:02Z</dc:date>
    </item>
  </channel>
</rss>

