Getting Data In

Fully disable perfmon

mavilla
Explorer

Hello all,

I am trying to fully disable perfmon from our splunk instance as we don not use this data to monitor any of the hosts. I have disabled the setting in Splunk Web and have the data is still there when I run the query to search for perfmon data. I've read on older posts on how to disable this feature, however, I do not have the Splunk_TA for windows folder as I've never had the app to use the perfmon data. Any other guidance on how to fully disable this feature?

Thanks

0 Karma

jscraig2006
Communicator

Are there UF that have the app installed? Also you might want to check SPLUNK_HOME/etc/system/local. If there is an inputs.conf with the stanza's in there.

0 Karma

mavilla
Explorer

there shouldn't be any UF with the app installed no

0 Karma

jscraig2006
Communicator

Sorry i edited my comment as you posted.. check SPLUNK_HOME/etc/system/local. If there is an inputs.conf with the stanza's in there

0 Karma

mavilla
Explorer

there is not a stanza for this in that file

0 Karma

jscraig2006
Communicator

do you have the Splunk_TA_microsoft_ad app installed? Run this command on on of the universal forwarder that is sending the data.

.\splunk.exe cmd btool inputs list --debug

0 Karma

mavilla
Explorer

I do not have this app installed either

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...