Getting Data In

Fully disable perfmon

mavilla
Explorer

Hello all,

I am trying to fully disable perfmon from our splunk instance as we don not use this data to monitor any of the hosts. I have disabled the setting in Splunk Web and have the data is still there when I run the query to search for perfmon data. I've read on older posts on how to disable this feature, however, I do not have the Splunk_TA for windows folder as I've never had the app to use the perfmon data. Any other guidance on how to fully disable this feature?

Thanks

0 Karma

jscraig2006
Communicator

Are there UF that have the app installed? Also you might want to check SPLUNK_HOME/etc/system/local. If there is an inputs.conf with the stanza's in there.

0 Karma

mavilla
Explorer

there shouldn't be any UF with the app installed no

0 Karma

jscraig2006
Communicator

Sorry i edited my comment as you posted.. check SPLUNK_HOME/etc/system/local. If there is an inputs.conf with the stanza's in there

0 Karma

mavilla
Explorer

there is not a stanza for this in that file

0 Karma

jscraig2006
Communicator

do you have the Splunk_TA_microsoft_ad app installed? Run this command on on of the universal forwarder that is sending the data.

.\splunk.exe cmd btool inputs list --debug

0 Karma

mavilla
Explorer

I do not have this app installed either

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...