I basically disabled all apps: splunk disable app <appname> (even SplunkForwarder & SplunkLightForwarder ) Note: Somehow, I couldn't disable eg. the search app!
With command splunk btool [inputs|outputs] list --debug , I could see paramaters Splunk's using while running. I noticed the search app's beeing used with a no-good inputs.conf file for me - so I removed that inputs.conf , since I couldn't disable the app itself.
Furher, in $SPLUNK_HOME/etc/system/local , I edited inputs.conf & outputs.conf as followed:
defaultGroup = indexserver.com_25000
disabled = false
indexAndForward = 0
autoLB = true
server = indexserver.com:25000
... View more