Splunk Enterprise

how to index hard disk only

New Member

guys, i have a little question.
I've been testing out splunk on windows version server. What i'm after is just retrieve only disk device logs only. the question is can splunk do that? I just need to monitor the disks of the servers. anyone on this subject. thanks advance..

Tags (2)
0 Karma

Splunk Employee
Splunk Employee

If your using the windows app, you should be able to comment out the scripted inputs in your under $SPLUNK_HOME\Splunk\etc\apps\windows\local\inputs.conf. Copy the scripted inputs from \Splunk\etc\apps\windows\default\inputs.conf and create a line under each stanza in the local file that says 'disabled = 1'

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!