Getting Data In

Universal Forwarder- Duplicate logs

Bill_B
Communicator

I have a Universal Forwarder on Win2008R2. The forwarder is reading Windows logs from a local file and forwarding to Splunk Enterprise. During setup, when prompted for what files to forward and the file path to read from, I selected "Security Logs" and "Forwarded Logs". Unfortunately the forwarder is now reading one event log and forwarding it as two logs; 1 labeled security logs and the other forwarded logs.

My Question is: What file do I need to change to get rid of either "Security Logs" or "Forwarded Logs"? (For example, I looked in $SPLUNK_HOME/etc/system/local/... inputs.conf and outputs.conf but I did not find the configuration in either location.)

Thank you.

0 Karma

Bill_B
Communicator

To solve this:

Modify file-
C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local\inputs.conf

All types of logs you don't want as a source should be edited to: "disable = 1"

The above file path is for a default install of Universal Forwarder on Windows2008R2.

0 Karma

lukejadamec
Super Champion

On the Splunk indexer, stop the remote inputs for the host.

Remote inputs are from wmi(configured on the indexer), local inputs are local(configured on the forwarder). They are both the same log file(s).

0 Karma

lukejadamec
Super Champion

I should have mentioned that you can confirm the duplicates are from using both local and remote sources by looking at the sources. WMI sources will contain 'WMI' in the name, and local ones won't.

0 Karma

lukejadamec
Super Champion

I think that depends on how they were configured. You will find them in the /etc/apps/someapp/local/wmi.conf file.

0 Karma

Bill_B
Communicator

What is the default location for remote inputs?
-Thanks

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...