One of my windows indexers is constantly writing to the btool log in DEBUG mode. I didn't build this environment, but I now manage it. Any reason why this would happen? I'm assuming it's something someone turned on in the past and never turned off. How do I go about disabling this?
Either check in the UI
Server settings » Server logging the
btool-support log channel or on the file system of the server goto
$SPLUNK_HOME/etc/ and check the settings in
log-local.cfg related to
Don forget to restart Splunk after any logging changes.
Hope this helps ...
Those are the default
.cfg files, you have to check if either the btool log channel is set to
debug or if for what ever reason Splunk is started in debug mode - see the docs http://docs.splunk.com/Documentation/Splunk/6.3.2/Troubleshooting/Enabledebuglogging