Getting Data In

How to use "remove monitor" to remove security event logs from my inputs

aywong
Path Finder

When I had initiall installed my forwarder I selected "security" as one of my inputs. Now I want to remove this as an input but when I type "list monitor" I don't know which input refers to the security one.

Tags (4)
0 Karma

yuvkca4
Engager

pretty old topic, but might be useful to someone:

$SPLUNK_HOME/etc/apps/search/local/inputs.conf

0 Karma

Mostafiz07
New Member

By following proper guidelines you can solve your problem.

0 Karma

gebr
Explorer

I downvoted this post because not helpful

0 Karma

scuilion
New Member

I downvoted this post because not productive

0 Karma

scuilion
New Member

/bin/splunk remove monitor /name/of/previous/monitor

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Just go to the inputs.conf file on the forwarder and look at the monitor settings. Remove what you don't want from the file and restart Splunk. See the link below.

http://docs.splunk.com/Documentation/Splunk/5.0/Data/Editinputs.conf

0 Karma

sdaniels
Splunk Employee
Splunk Employee

It must be located in another inputs.conf. Take a look at those as well.

http://docs.splunk.com/Documentation/Splunk/5.0/admin/Aboutconfigurationfiles

0 Karma

anoopambli
Communicator

I checked inputs.conf file under $SPLUNK_HOME/etc/system/local/ but dont see any reference for Application eventlog. Am i looking at the right inputs.conf file?

0 Karma

anoopambli
Communicator

I have the same issue, while installing the forwarder i have selected application and system eventlog as input and now i dont need that anymore. What needs to be done to stop sending the eventlog data to indexer?

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...