Getting Data In

Perfmon sending logs to the wrong indexer

splunktrainingu
Communicator

I have a single instance deployment. I have a server that is sending Perfmon logs to my main index but I never told it to send those logs. Where do I check those settings? I want to keep it sending logs but to the correct index. So I made a perfmon index but I cannot find where on the server this configuration files is. I checked etc/system/local couldn't find anything.

Labels (1)
Tags (1)
0 Karma
1 Solution

splunktrainingu
Communicator

I was able to find that there was an application called Splunk TA (splunkuniversalforwarder/etc/apps) which resided on that machine simply deleted it because I know I do not have this on my fresh install of Splunk so it won't be pushed out again also checked my deployment server and made sure it is none existent there.

View solution in original post

0 Karma

splunktrainingu
Communicator

I was able to find that there was an application called Splunk TA (splunkuniversalforwarder/etc/apps) which resided on that machine simply deleted it because I know I do not have this on my fresh install of Splunk so it won't be pushed out again also checked my deployment server and made sure it is none existent there.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...