I have one data input which is creating daemon in Linux Environment and reading data and keeps creating file in local directory. There is script to remove old files in the data input it self. But whenever user disables the app old files getting piled up because daemon is not stopped. So is there any way in splunk in which we can execute some script/pythonscript before enable or disable the app?
The scripted input is deployed on UF or Splunk Enterprise instance?
Splunk Enterprise Instance..