Getting Data In

After removing a monitor on one log file from all my Splunk forwarders, why do I still see search results for that log file?

smanda
New Member

I removed a monitor on one log file from all the Splunk forwarders in the inputs.conf file and restarted Splunk forwarder and Splunk indexers. However, we still see the new logs been indexed and search results returned.

0 Karma

ddrillic
Ultra Champion

What is the btool telling on the forwarders?

 ./splunk cmd btool inputs list monitor

Is it listing the removed files?

0 Karma

smanda
New Member

Output of the command is not listing the removed files.

0 Karma

ddrillic
Ultra Champion

And you see fresh data from this particular host on which you ran the btool command, right? Doesn't make any sense.

Anybody has any idea?

0 Karma

smanda
New Member

Yes. Its showing the monitors which we configured in inputs.conf right now.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...