Getting Data In

How can I completely disable forwarders take any more spaces then just splunk s/w?


I had instances where many of my forwaders filled up disk partition to go full.

How can I disable all logging? Ofcourse I have selected "store local copy" as no.

Thanks, Gurus!

Tags (1)
0 Karma

Splunk Employee
Splunk Employee

You can adjust Splunk local logging configurations in $SPLUNK_HOME/etc/log.cfg

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!