Getting Data In

Are any default apps in universal forwarder unnecessary?

hectorvp
Communicator

I just installed universal forwarder,

And was deploying my first app using DS, I came accros few apps in place prior to what I configure on UF.

Path: \etc\apps\ 

Apps found are:

introspection_generator_addon

learned

searched

splunk_httpinput

splunk_internal_metrics

SplunkUniversalForwarder

 

Is any them unnecessary and can I remove?

 

 

 

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Any apps already in place before the UF receives anything from the DS is standard Splunk and shouldn't be touched.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Any apps already in place before the UF receives anything from the DS is standard Splunk and shouldn't be touched.

---
If this reply helps you, Karma would be appreciated.

Jagadeesh2022
Path Finder

Hi @richgalloway 

In my case, more volume of data produced from Learned app. Is there any possibility to disable this app: learned? 

If we can't disable how to stop generate logs from this app: learned ?

Your response is much appreciated. 

Regards,

Jagadeesh

@gcusello @ITWhisperer 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

This question is more than 2 years old with an accepted answer.  You should have posted a new question.

The learned app is invoked when data is received without a sourcetype.  To avoid using the app, ensure all data ingested by Splunk has a sourcetype associated with it and that sourcetype is configured in props.conf.

---
If this reply helps you, Karma would be appreciated.

Jagadeesh2022
Path Finder

@richgalloway 

Sorry to updated in the older question.  

Thanks for your response.  My last question. If we just mention sourcetype in input.conf  is not enough?

I should to mention the same sourcetype again in props.conf ?  

Thanks in advance. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If a sourcetype is not in props.conf then it doesn't exist.  Mentioning it in inputs.conf alone is not enough.  Props.conf is where the properties of the sourcetype are specified.  Without them, Splunk has to guess about the sourcetype and often guesses wrong.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...