Getting Data In

How do I delete a duplicate data input

udiggity
New Member

Somehow I have a duplicate remote directory input listed in my inputs it is in the format ///servername//direcotory// I also have it listed with the proper UNC path like \servername\director\ Both seem to be collecting. When I try to remove the first one I get the error Error occurred attempting to disable \\ncmec-radius\service\: In handler 'monitor': Object disabling requires user and application to be specified.

Any idea how I remove this?

Tags (2)
0 Karma
1 Solution

netwrkr
Communicator

I'm not a Windows guy but...assuming Splunk *nix operates in the same way. Go to where the 'inputs.conf' file is - typically $SPLUNK_HOME/etc/apps/search/local/ and remove the duplicate directory entry. I would recommend first stopping splunk, editing the file, and then restarting.

View solution in original post

netwrkr
Communicator

I'm not a Windows guy but...assuming Splunk *nix operates in the same way. Go to where the 'inputs.conf' file is - typically $SPLUNK_HOME/etc/apps/search/local/ and remove the duplicate directory entry. I would recommend first stopping splunk, editing the file, and then restarting.

netwrkr
Communicator

Marking my answer as helpful is always appreciated 🙂

0 Karma

udiggity
New Member

Thanks, that did it!

0 Karma

udiggity
New Member

Thanks I will try this now.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...