Monitoring Splunk

Cannot stop capturing events for localhost

kgeil
Explorer

Hi, I have Splunk set up on my workstation, but do not want to monitor the workstation itself. I have gone to Manager » Data inputs » Event log collections » localhost, and cleared all selected logs (application, security, and system), and hit save. When I go back there, however, these three logs are back in the Selected Log(s) box. I have disabled all other data inputs, but still, I get events for my workstation. Am I doing something wrong? Do I need to send these events to a nullqueue, as described in the link below?

http://docs.splunk.com/Documentation/Splunk/4.2.4/Deploy/Routeandfilterdatad

Thanks,

Kevin

Tags (1)
0 Karma

gpt
New Member

Hello. I'm interested in doing something like that because of the license's warnings. I'm monitorizing several servers from my computer but I don't want my computer's logs at all. I noticed the most info Splunk get is from my computer so I already have 3 warnings!

I have tried to put my computer's info into another index and disable it but I'm not sure that's going to work. I'd like to send my computer's info to a null queue and I tried but I wasn't able.

What exactly do I have to modify in outputs.conf? What about props.conf?
I'll aprecciate any help!

Thank you!!

PD. Sorry about my English!

0 Karma

kgeil
Explorer

Cool, Thank you. I'll be checking that out tomorrow. If you know of a link for editing outputs.conf, I'd love to read it (I'm not in front of my splunk installation right now, so I can't read the file itself).

Thanks again,

Kevin

0 Karma

gekoner
Communicator

Yes you need to either send them to a null queue or if you don't want ANY data from your local host, remove or edit your outputs.conf file

0 Karma

kgeil
Explorer

I have cleaned out all indexes. They begin showing up immediately after that, all new events.

Thanks,

Kevin

0 Karma

rroberts
Splunk Employee
Splunk Employee

Are you just seeing old indexed events? Have you cleaned out the index? Or are new events still coming in?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...