Splunk Enterprise

How do I remove the remote wmi data sources from splunk light?

bpeer
Engager

I set up splunk light and configured remote windows eventlog monitoring. Then I started reading about the Universal forwarders. Now I want to switch everything over to the UF but the ones I have set up are now listed twice as search hosts. How do I remove the wmi data collectors?

Tags (3)
0 Karma
1 Solution

adonio
Ultra Champion

hi bpeer,
placing here to close the question
you can try to go to settings (top right) -> data inputs -> Remote Events Log Collection -> look for your WMI inputs. -> disable or delete
hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

hi bpeer,
placing here to close the question
you can try to go to settings (top right) -> data inputs -> Remote Events Log Collection -> look for your WMI inputs. -> disable or delete
hope it helps

0 Karma

bpeer
Engager

That is what I was looking for. Thank you adonio.

Brad

0 Karma

adonio
Ultra Champion

hi bpeer,
you can try to go to settings (top right) -> data inputs -> Remote Events Log Collection -> look for your WMI inputs. -> disable or delete
hope it helps

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...