Monitoring Splunk

Cannot stop capturing events for localhost

kgeil
Explorer

Hi, I have Splunk set up on my workstation, but do not want to monitor the workstation itself. I have gone to Manager » Data inputs » Event log collections » localhost, and cleared all selected logs (application, security, and system), and hit save. When I go back there, however, these three logs are back in the Selected Log(s) box. I have disabled all other data inputs, but still, I get events for my workstation. Am I doing something wrong? Do I need to send these events to a nullqueue, as described in the link below?

http://docs.splunk.com/Documentation/Splunk/4.2.4/Deploy/Routeandfilterdatad

Thanks,

Kevin

Tags (1)
0 Karma

gpt
New Member

Hello. I'm interested in doing something like that because of the license's warnings. I'm monitorizing several servers from my computer but I don't want my computer's logs at all. I noticed the most info Splunk get is from my computer so I already have 3 warnings!

I have tried to put my computer's info into another index and disable it but I'm not sure that's going to work. I'd like to send my computer's info to a null queue and I tried but I wasn't able.

What exactly do I have to modify in outputs.conf? What about props.conf?
I'll aprecciate any help!

Thank you!!

PD. Sorry about my English!

0 Karma

kgeil
Explorer

Cool, Thank you. I'll be checking that out tomorrow. If you know of a link for editing outputs.conf, I'd love to read it (I'm not in front of my splunk installation right now, so I can't read the file itself).

Thanks again,

Kevin

0 Karma

gekoner
Communicator

Yes you need to either send them to a null queue or if you don't want ANY data from your local host, remove or edit your outputs.conf file

0 Karma

kgeil
Explorer

I have cleaned out all indexes. They begin showing up immediately after that, all new events.

Thanks,

Kevin

0 Karma

rroberts
Splunk Employee
Splunk Employee

Are you just seeing old indexed events? Have you cleaned out the index? Or are new events still coming in?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...