Getting Data In

Is there another way to block a host without redirecting the events to null queue by indexer?

kteng2024
Path Finder

i have blocked a host in such way that all the events from that host will be redirected to Null Queue by the indexers. But indexers have to do some work to redirect. So, can i please know is there any other way to block that host without redirecting the events to null queue by indexer?

0 Karma

woodcock
Esteemed Legend

You have many options if you are blocking literally everything (which is what you said):

o If you are using a Splunk Deployment Server (you definitely should be), blacklist that host inside all serverclasses.
o Stop (or better yet, uninstall) Splunk on the forwarder.
o Use an OS-level feature (you did not say what host OS is on your Indexers) to block the host (e.g. firewalld, null-route, etc.)

If you are only blocking some things, then the only other way is to send the stuff to an intermediate facility and manage the data there. Almost always this is done with a Heavy Forwarder running Syslog.

0 Karma

somesoni2
SplunkTrust
SplunkTrust

How is the monitoring done for that host, inputs.conf deployed on that host? If yes then you can just get that inputs.conf removed from that host.

0 Karma

kteng2024
Path Finder

i want to block all the events from that host but not increasing indexerperformance.

0 Karma

somesoni2
SplunkTrust
SplunkTrust

Yes, if you remove all the inputs.conf from the forwarders, it will not be monitoring and sending data to your indexers, so zero impact on indexers. Are you using deployment server to maintain your data inputs on forwarder OR you create inputs.conf directly on forwarders?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...