Getting Data In

How to disable perfmon index in one of the cluster?

sag5757
Explorer

In my enviroment there are 2 indexer cluster .i.e. cluster 1 and cluster 2. I need to disable perfmon index in cluster 1. i need to disable this index in the cluster for the time being. In future , maybe it is required to re enable the index. So, what will be the workaround for that. Do we need to route data to null queue or do we need to create the lastchance index. 

Labels (1)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
What problem are you trying to solve?
You can disable the index easily enough, but if data is still being sent to that index you will have a lot of banner messages complaining about a "missing or disabled index". IMO, you should turn off the perfmon inputs before disabling the index.
---
If this reply helps you, Karma would be appreciated.
0 Karma

sag5757
Explorer

All servers mentioned that are sending data to perfmon index in cluster 1 are DNS and AD servers.So, they are sending directly to the cluster.I have tried turning off the perfmon inputs but still we are receiving data on the index

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
Disabling the index will not stop the data from coming in. As I mentioned, doing so will cause a lot of banner messages to appear. Creating a lastChange index would be the same as leaving perfmon in place.
Did you restart Splunk on the servers so the input changes take effect?
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

ATTENTION!! We’re MOVING (not really)

Hey, all! In an effort to keep this Slack workspace secure and also to make our new members' experience easy, ...

Splunk Admins: Build a Smarter Stack with These Must-See .conf25 Sessions

  Whether you're running a complex Splunk deployment or just getting your bearings as a new admin, .conf25 ...

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...