Getting Data In

Where do I find data being collected for CPU, RAM in Splunk Ent. Data Inputs for my Windows & Unix hosts?

SamHTexas
Builder

Where do I find data being collected for CPU, RAM in Splunk Ent. Data Inputs for my Windows & Unix hosts? I need this as part of cutting the fat from the license usage. Is there a best practices document to trim such data that is either redundant or useless? Thank u

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check the inputs.conf files on your forwarders.  Turn off the performance inputs you don't need and increase the interval for those you still want.

---
If this reply helps you, Karma would be appreciated.
0 Karma

SamHTexas
Builder

Thank u sir. What u described has to be done via CLI I have learned. I also have found the the same under settings-->Data Inputs for local & remote sources. But I can not do much editing of the values you are talking about right? Can the settings & values be all changed via GUI as well? Please advise.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you can use the GUI to change those settings, but if you have more than a couple of forwarders then all those clicks will be time consuming and error-prone.  Better to make the changes to an app (using the CLI - it's not a four-letter word) on your DS and push the new settings from there.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...