Getting Data In

How to use "remove monitor" to remove security event logs from my inputs

aywong
Path Finder

When I had initiall installed my forwarder I selected "security" as one of my inputs. Now I want to remove this as an input but when I type "list monitor" I don't know which input refers to the security one.

Tags (4)
0 Karma

yuvkca4
Engager

pretty old topic, but might be useful to someone:

$SPLUNK_HOME/etc/apps/search/local/inputs.conf

0 Karma

Mostafiz07
New Member

By following proper guidelines you can solve your problem.

0 Karma

gebr
Explorer

I downvoted this post because not helpful

0 Karma

scuilion
New Member

I downvoted this post because not productive

0 Karma

scuilion
New Member

/bin/splunk remove monitor /name/of/previous/monitor

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Just go to the inputs.conf file on the forwarder and look at the monitor settings. Remove what you don't want from the file and restart Splunk. See the link below.

http://docs.splunk.com/Documentation/Splunk/5.0/Data/Editinputs.conf

0 Karma

sdaniels
Splunk Employee
Splunk Employee

It must be located in another inputs.conf. Take a look at those as well.

http://docs.splunk.com/Documentation/Splunk/5.0/admin/Aboutconfigurationfiles

0 Karma

anoopambli
Communicator

I checked inputs.conf file under $SPLUNK_HOME/etc/system/local/ but dont see any reference for Application eventlog. Am i looking at the right inputs.conf file?

0 Karma

anoopambli
Communicator

I have the same issue, while installing the forwarder i have selected application and system eventlog as input and now i dont need that anymore. What needs to be done to stop sending the eventlog data to indexer?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...