Splunk Enterprise

disable splunk stream

iherb_0718
Path Finder

Anyone have the directions handy to disable splunk stream on a particular server? Is it done via the splunk stream app?

I want to disable it in a way that the service will not start up when the server reboots.

Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

This is default group that catches forwarders if no other group matches.

You should create a new group and move your stream setups to new one. Setup match forwarders regex to match only your server that you want. This will be your active configuration point.

Default group should not contain any stream. Your unwanted server will be seen under this default group and does not listen any stream.

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @iherb_0718,

You can remove that particular server from Forwarder groups on Splunk Stream App | Distributed Forwarder Management.

Streamfwd service will start but not start listening.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

iherb_0718
Path Finder

Within the Stream app < configuration < distributed forwarder management < There is a default group and MATCHED FORWARDERS but that link is not editable. 

 

0 Karma

alonsocaio
Contributor

HI @iherb_0718,

How are you deploying the Splunk Stream app to your servers? Are you using a deployment server? If so, you could try removing your server from the server class that deploys this app. I guess this would uninstall the Splunk Stream app from the server.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...