Getting Data In

How can I disable Splunk Universals Forwarder input after installing Splunk TA_windows via deployment?

jjacksonVirtus
New Member

I currently have a Splunk Universal Forwarder installed on all my servers. It was recommended by Splunk to install the TA_windows plug-in on top of the Universal Forwarder. I built out a deployment from the Search Head to deploy TA_windows add-on to my servers but I noticed the regular Universal forwarder input.conf is still active/enabled along with the TA_windows add-on.
How can I disable the regular Universal Forwarder app automatically when using the TA_windows add-on.

0 Karma
1 Solution

tiagofbmm
Influencer

Can you change that inputs.conf in the app in the deployment server and then do a splunk reload deploy server?

That will get you the fresh version of the app with the input disabled.

View solution in original post

0 Karma

ddrillic
Ultra Champion

Keep in mind that multiple input.conf is a feature and not a distraction. Meaning, each input.confbrings its needs to the table and all of them are being aggregated together. So, as long as they don't conflict each other they can coexist according to the beloved - live and let live idea.

0 Karma

tiagofbmm
Influencer

Can you change that inputs.conf in the app in the deployment server and then do a splunk reload deploy server?

That will get you the fresh version of the app with the input disabled.

0 Karma

tiagofbmm
Influencer

Please let me know if the answer was useful for you. If it was, accept it and upvote. If not, give us more input so we can help you with that

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...