Deployment Architecture

Disable lightweight forwarding in 4.1 from command line

tepperso
Engager

I stupidly enabled Lightweight forwarding from the web interface and now I can't get the web interference to load. How can I Disable lightweight forwarding from Linux command line so that I can get things back to normal. I'm using 4.1 so the set server-type no longer works.

Tags (2)
0 Karma
1 Solution

CerielTjuh
Path Finder

In the app.conf file located in your etc\apps\SplunkLightForwarder\local folder adjust the settings to:

[install]
state = disabled

and then restart your Splunk instance, this will do the trick.

splunk disable app SplunkLightForwarder

will do the trick as well

View solution in original post

tepperso
Engager

I finally found the documentation for this feature for v4.1. http://www.splunk.com/base/Documentation/4.1.2/Admin/Enableforwardingandreceiving

./splunk disable app [SplunkForwarder|SplunkLightForwarder] -auth [username]:[password]

CerielTjuh
Path Finder

In the app.conf file located in your etc\apps\SplunkLightForwarder\local folder adjust the settings to:

[install]
state = disabled

and then restart your Splunk instance, this will do the trick.

splunk disable app SplunkLightForwarder

will do the trick as well

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...