Getting Data In

Perfmon sending logs to the wrong indexer

splunktrainingu
Communicator

I have a single instance deployment. I have a server that is sending Perfmon logs to my main index but I never told it to send those logs. Where do I check those settings? I want to keep it sending logs but to the correct index. So I made a perfmon index but I cannot find where on the server this configuration files is. I checked etc/system/local couldn't find anything.

Labels (1)
Tags (1)
0 Karma
1 Solution

splunktrainingu
Communicator

I was able to find that there was an application called Splunk TA (splunkuniversalforwarder/etc/apps) which resided on that machine simply deleted it because I know I do not have this on my fresh install of Splunk so it won't be pushed out again also checked my deployment server and made sure it is none existent there.

View solution in original post

0 Karma

splunktrainingu
Communicator

I was able to find that there was an application called Splunk TA (splunkuniversalforwarder/etc/apps) which resided on that machine simply deleted it because I know I do not have this on my fresh install of Splunk so it won't be pushed out again also checked my deployment server and made sure it is none existent there.

0 Karma
Get Updates on the Splunk Community!

Set Up More Secure Configurations in Splunk Enterprise With Config Assist

This blog post is part 3 of 4 of a series on Splunk Assist. Click the links below to see the other ...

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...

Enterprise Security Content Update (ESCU) v3.54.0

The Splunk Threat Research Team (STRT) recently released Enterprise Security Content Update (ESCU) v3.54.0 and ...