Getting Data In

Error deleting data input

spersels
New Member

So I'll ask again since previous question seems to have been lost. Sorry if this appears to be a duplicate. I'm getting the following error and cannot delete this data input.

Error occurred attempting to remove <data input>: In handler 'remote_monitor': The following required arguments are missing: app_name..

Tags (2)
0 Karma

jmorgan_
Explorer

As a new Splunk user, this is hugely frustrating. Trying to get even a basic setup going feels like walking through a minefield. Not being able to remove Data Inputs from the web console and then having to find which inputs.conf these settings are stored in. When you combine it with the fact that you cannot edit Server Classes (see here), the new user experience is pretty awful. Splunk seems like a great tool, but it is hard to justify the time to get it up and running. There is a difference between complicated and buggy.

jmorgan_
Explorer
0 Karma

BlueSocket
Contributor

Hi! I am also having the same problem with one of my data inputs and I cannot do anything with it at all.

Does anyone know what I can do with my data input? I am using Splunk 6.2.3.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you have access to the CLI, edit the inputs.conf file to remove the `` stanza. Then restart Splunk. The trick is finding the right file to modify. Start with SPLUNK_HOME/etc/system/local/inputs.conf then look in SPLUNK_HOME/etc/apps/*/local/inputs.conf.

---
If this reply helps you, Karma would be appreciated.
0 Karma

spersels
New Member

I see the stanza on the forwarder in C:\Program Files\SplunkUniversalForwarder\etc\apps\_server_app_Laptops\local\inputs.conf.

1) Do I need to use the CLI to delete the entry or can I use notepad?

2) Is there anything I need to do on the master - i.e. once I delete it from the forwarder will master pick that up remove the that item from the list on the Data Inputs screen

3) this happens frequently. Is this a know problem? Is there something I'm doing that's causing this? I'm not editing any config files manually or any other fancy/intrusive stuff. Just using the web adminstration tools provided out of the box. This is a bare bones, newly installed uncustomized 6.2 install. One enterprise server and one universal forwarder. Enterprise running on Windows 2012, universal forwarder running on Windows 7.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...