All Apps and Add-ons

Splunk Add-on for Microsoft Windows: How to disable this add-on on all Universal Forwarders?

Contributor

If i wanted to disable Splunk Add-on for Microsoft Windows on all Universal Forwarders (6.4.4) and only use my own app to collect Windows logs, what would be the best way to do this? I was going to make a directory in deployment apps named the same thing as the app on the UF's "splunktawindows" and set it to disable in app.conf.

any thoughts?

0 Karma
1 Solution

Legend

Hi sbattista09,
go in your Deployment Server and delete splunktawindows from all your Server Classes.
Bye.
Giuseppe

View solution in original post

Legend

Hi sbattista09,
go in your Deployment Server and delete splunktawindows from all your Server Classes.
Bye.
Giuseppe

View solution in original post

Contributor

I do not have that defined in my server classes.

0 Karma

Legend

Hi sbattista09
This means that in your installation procedure you flagged the Windows flags.
So, create a Server Class containing all your windows server, insert in it a disabled version of splunktawindows and deploy it.
This should disable your TA.
Bye.
Giuseppe

0 Karma