Splunk Enterprise

How do I remove the remote wmi data sources from splunk light?

bpeer
Engager

I set up splunk light and configured remote windows eventlog monitoring. Then I started reading about the Universal forwarders. Now I want to switch everything over to the UF but the ones I have set up are now listed twice as search hosts. How do I remove the wmi data collectors?

Tags (3)
0 Karma
1 Solution

adonio
Ultra Champion

hi bpeer,
placing here to close the question
you can try to go to settings (top right) -> data inputs -> Remote Events Log Collection -> look for your WMI inputs. -> disable or delete
hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

hi bpeer,
placing here to close the question
you can try to go to settings (top right) -> data inputs -> Remote Events Log Collection -> look for your WMI inputs. -> disable or delete
hope it helps

0 Karma

bpeer
Engager

That is what I was looking for. Thank you adonio.

Brad

0 Karma

adonio
Ultra Champion

hi bpeer,
you can try to go to settings (top right) -> data inputs -> Remote Events Log Collection -> look for your WMI inputs. -> disable or delete
hope it helps

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...