Greetings all.
I'm relatively new to Splunk and did not see an answer for this particular issue in the KB. Any help is appreciated. I have alerts turned on for missing forwarders and am being notified every 15 minutes that one is missing. After a small amount of investigation, I found that this Windows host has been permanently powered down. I would like to remove this host, not only from alerting, but from Splunk Cloud all together. I DO need to keep its historical data as we are in the Financial Tech industry and our retention policies are auditable. Does anyone know how to remove said host, but keep a record that it was there before removing it? Thank you very much. If there is any more information necessary, I would be happy to provide it.
... View more