Getting Data In
Highlighted

Stop Splunk Forwarder when log limit reached

Communicator

Hi there,

is there a way to stop a Splunk Forwarder when its sending more then for instance 2 GB ?
From a SearchHead I could configure an alert which appear if a Forwarder logs more than 2 GB. But after appearing the alert, is there a way to stop the Splunk Forwarder deamon via REST API or start a other script which can stop the Forwarder via Port 8089 ?
The problem is I just can reach the known ports, I can not access via SSH to the Forwarders.

Thank you

Regards

Tags (2)
0 Karma
Highlighted

Re: Stop Splunk Forwarder when log limit reached

Communicator

Hi,

I solved the problem with using limits.conf (max troughput).

greetings

View solution in original post

0 Karma