Hello. I'm interested in doing something like that because of the license's warnings. I'm monitorizing several servers from my computer but I don't want my computer's logs at all. I noticed the most info Splunk get is from my computer so I already have 3 warnings!
I have tried to put my computer's info into another index and disable it but I'm not sure that's going to work. I'd like to send my computer's info to a null queue and I tried but I wasn't able.
What exactly do I have to modify in outputs.conf? What about props.conf?
I'll aprecciate any help!
Thank you!!
PD. Sorry about my English!
... View more