Getting Data In

How to use "remove monitor" to remove security event logs from my inputs

aywong
Path Finder

When I had initiall installed my forwarder I selected "security" as one of my inputs. Now I want to remove this as an input but when I type "list monitor" I don't know which input refers to the security one.

Tags (4)
0 Karma

yuvkca4
Engager

pretty old topic, but might be useful to someone:

$SPLUNK_HOME/etc/apps/search/local/inputs.conf

0 Karma

Mostafiz07
New Member

By following proper guidelines you can solve your problem.

0 Karma

gebr
Explorer

I downvoted this post because not helpful

0 Karma

scuilion
New Member

I downvoted this post because not productive

0 Karma

scuilion
New Member

/bin/splunk remove monitor /name/of/previous/monitor

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Just go to the inputs.conf file on the forwarder and look at the monitor settings. Remove what you don't want from the file and restart Splunk. See the link below.

http://docs.splunk.com/Documentation/Splunk/5.0/Data/Editinputs.conf

0 Karma

sdaniels
Splunk Employee
Splunk Employee

It must be located in another inputs.conf. Take a look at those as well.

http://docs.splunk.com/Documentation/Splunk/5.0/admin/Aboutconfigurationfiles

0 Karma

anoopambli
Communicator

I checked inputs.conf file under $SPLUNK_HOME/etc/system/local/ but dont see any reference for Application eventlog. Am i looking at the right inputs.conf file?

0 Karma

anoopambli
Communicator

I have the same issue, while installing the forwarder i have selected application and system eventlog as input and now i dont need that anymore. What needs to be done to stop sending the eventlog data to indexer?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...