I'm using Splunk6.0.
I tried to disable a data input monitor by CLI (/opt/splunk/bin/splunk edit monitor '/var/log/messages' -disable 1 -auth admin:password). Display shows "Modified monitor of '/var/log/messages'", however it seems that it is not changed.
(I referred to http://docs.splunk.com/Documentation/Splunk/6.0/Data/MonitorfilesanddirectoriesusingtheCLI)
Is it impossible to disable a data input by CLI?
... View more