Dashboards & Visualizations

How do I remove hosts from the Forward and Receiving dashboard in the Distributed Management Console?

slebbie_splunk
Splunk Employee
Splunk Employee

I've disabled and removed the hosts from tcpoutput stanzas via the outputs.conf file, but the old hosts are still in the Distributed Management Console Why?

Whenever I try to remove the hosts, it says [tcpoutput://ipaddress] not found in outputs.conf. How do I remove it from the DMC completely?

*This is a question I am answering on my own because it took me a while to figure it out and I know that it may bother other folks out there so hope this helps.

0 Karma
1 Solution

hunters_splunk
Splunk Employee
Splunk Employee

Hi slebbie,

Are you referring to the Forwarders: Deployment dashboard in Monitoring Console?
If you have stopped a forwarder from forwarding data to an indexer by removing the corresponding stanza from output.conf on forwarder, the forwarder will still be displayed on the dashboard but in missing (inactive) status.
You can filter out missing forwarders from some of the dashboard panels, but to completely remove the forwarder from the dashboard, you need to tamper with the metrics log and delete the related logs from source = /Applications/Splunk/var/log/splunk/metrics.log. Not sure this is what you want to do.

Hope this helps. Thanks!
Hunter

View solution in original post

putnamblake
Path Finder

If we are talking about removing the hosts which are labeled as "missing" from MC>Forwarders> Forwarders Deployment then we are able to rebuild the Forwarders Asset Table to remove decomm'd host from the dashboard/ report. 

 

https://docs.splunk.com/Documentation/Splunk/8.0.4/DMC/Configureforwardermonitoring#Rebuild_the_forw...

0 Karma

slebbie_splunk
Splunk Employee
Splunk Employee

Hi Hunters,

I totally forgot to respond to this question. Thanks for the assist.

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi slebbie,

Are you referring to the Forwarders: Deployment dashboard in Monitoring Console?
If you have stopped a forwarder from forwarding data to an indexer by removing the corresponding stanza from output.conf on forwarder, the forwarder will still be displayed on the dashboard but in missing (inactive) status.
You can filter out missing forwarders from some of the dashboard panels, but to completely remove the forwarder from the dashboard, you need to tamper with the metrics log and delete the related logs from source = /Applications/Splunk/var/log/splunk/metrics.log. Not sure this is what you want to do.

Hope this helps. Thanks!
Hunter

ppablo
Retired

Hi @slebbie_splunk

Did you forget to post your answer in the "Enter your answer here..." field below?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...