Getting Data In

Is there another way to block a host without redirecting the events to null queue by indexer?

kteng2024
Path Finder

i have blocked a host in such way that all the events from that host will be redirected to Null Queue by the indexers. But indexers have to do some work to redirect. So, can i please know is there any other way to block that host without redirecting the events to null queue by indexer?

0 Karma

woodcock
Esteemed Legend

You have many options if you are blocking literally everything (which is what you said):

o If you are using a Splunk Deployment Server (you definitely should be), blacklist that host inside all serverclasses.
o Stop (or better yet, uninstall) Splunk on the forwarder.
o Use an OS-level feature (you did not say what host OS is on your Indexers) to block the host (e.g. firewalld, null-route, etc.)

If you are only blocking some things, then the only other way is to send the stuff to an intermediate facility and manage the data there. Almost always this is done with a Heavy Forwarder running Syslog.

0 Karma

somesoni2
Revered Legend

How is the monitoring done for that host, inputs.conf deployed on that host? If yes then you can just get that inputs.conf removed from that host.

0 Karma

kteng2024
Path Finder

i want to block all the events from that host but not increasing indexerperformance.

0 Karma

somesoni2
Revered Legend

Yes, if you remove all the inputs.conf from the forwarders, it will not be monitoring and sending data to your indexers, so zero impact on indexers. Are you using deployment server to maintain your data inputs on forwarder OR you create inputs.conf directly on forwarders?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...