Archive

Cannot stop capturing events for localhost

kgeil
Explorer

Hi, I have Splunk set up on my workstation, but do not want to monitor the workstation itself. I have gone to Manager » Data inputs » Event log collections » localhost, and cleared all selected logs (application, security, and system), and hit save. When I go back there, however, these three logs are back in the Selected Log(s) box. I have disabled all other data inputs, but still, I get events for my workstation. Am I doing something wrong? Do I need to send these events to a nullqueue, as described in the link below?

http://docs.splunk.com/Documentation/Splunk/4.2.4/Deploy/Routeandfilterdatad

Thanks,

Kevin

Tags (1)
0 Karma

gpt
New Member

Hello. I'm interested in doing something like that because of the license's warnings. I'm monitorizing several servers from my computer but I don't want my computer's logs at all. I noticed the most info Splunk get is from my computer so I already have 3 warnings!

I have tried to put my computer's info into another index and disable it but I'm not sure that's going to work. I'd like to send my computer's info to a null queue and I tried but I wasn't able.

What exactly do I have to modify in outputs.conf? What about props.conf?
I'll aprecciate any help!

Thank you!!

PD. Sorry about my English!

0 Karma

kgeil
Explorer

Cool, Thank you. I'll be checking that out tomorrow. If you know of a link for editing outputs.conf, I'd love to read it (I'm not in front of my splunk installation right now, so I can't read the file itself).

Thanks again,

Kevin

0 Karma

gekoner
Communicator

Yes you need to either send them to a null queue or if you don't want ANY data from your local host, remove or edit your outputs.conf file

0 Karma

kgeil
Explorer

I have cleaned out all indexes. They begin showing up immediately after that, all new events.

Thanks,

Kevin

0 Karma

rroberts
Splunk Employee
Splunk Employee

Are you just seeing old indexed events? Have you cleaned out the index? Or are new events still coming in?

0 Karma