I removed a monitor on one log file from all the Splunk forwarders in the inputs.conf file and restarted Splunk forwarder and Splunk indexers. However, we still see the new logs been indexed and search results returned.
What is the btool telling on the forwarders?
./splunk cmd btool inputs list monitor
Is it listing the removed files?
Output of the command is not listing the removed files.
And you see fresh data from this particular host on which you ran the btool command, right? Doesn't make any sense.
Anybody has any idea?
Yes. Its showing the monitors which we configured in inputs.conf right now.