Getting Data In

Perfmon sending logs to the wrong indexer

splunktrainingu
Communicator

I have a single instance deployment. I have a server that is sending Perfmon logs to my main index but I never told it to send those logs. Where do I check those settings? I want to keep it sending logs but to the correct index. So I made a perfmon index but I cannot find where on the server this configuration files is. I checked etc/system/local couldn't find anything.

Labels (1)
Tags (1)
0 Karma
1 Solution

splunktrainingu
Communicator

I was able to find that there was an application called Splunk TA (splunkuniversalforwarder/etc/apps) which resided on that machine simply deleted it because I know I do not have this on my fresh install of Splunk so it won't be pushed out again also checked my deployment server and made sure it is none existent there.

View solution in original post

0 Karma

splunktrainingu
Communicator

I was able to find that there was an application called Splunk TA (splunkuniversalforwarder/etc/apps) which resided on that machine simply deleted it because I know I do not have this on my fresh install of Splunk so it won't be pushed out again also checked my deployment server and made sure it is none existent there.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...