Getting Data In

How to use "remove monitor" to remove security event logs from my inputs

aywong
Path Finder

When I had initiall installed my forwarder I selected "security" as one of my inputs. Now I want to remove this as an input but when I type "list monitor" I don't know which input refers to the security one.

Tags (4)
0 Karma

yuvkca4
Engager

pretty old topic, but might be useful to someone:

$SPLUNK_HOME/etc/apps/search/local/inputs.conf

0 Karma

Mostafiz07
New Member

By following proper guidelines you can solve your problem.

0 Karma

gebr
Explorer

I downvoted this post because not helpful

0 Karma

scuilion
New Member

I downvoted this post because not productive

0 Karma

scuilion
New Member

/bin/splunk remove monitor /name/of/previous/monitor

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Just go to the inputs.conf file on the forwarder and look at the monitor settings. Remove what you don't want from the file and restart Splunk. See the link below.

http://docs.splunk.com/Documentation/Splunk/5.0/Data/Editinputs.conf

0 Karma

sdaniels
Splunk Employee
Splunk Employee

It must be located in another inputs.conf. Take a look at those as well.

http://docs.splunk.com/Documentation/Splunk/5.0/admin/Aboutconfigurationfiles

0 Karma

anoopambli
Communicator

I checked inputs.conf file under $SPLUNK_HOME/etc/system/local/ but dont see any reference for Application eventlog. Am i looking at the right inputs.conf file?

0 Karma

anoopambli
Communicator

I have the same issue, while installing the forwarder i have selected application and system eventlog as input and now i dont need that anymore. What needs to be done to stop sending the eventlog data to indexer?

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...