How to prevent events from being indexed by splunk?
Answer / Javed Siddique
To prevent events from being indexed by Splunk, you can create a forwarder configuration file with a 'disableLocalInput' attribute set to 'true'. Additionally, you can also use the 'inhibit-local-inputs.conf' file on the forwarder for similar purposes.
| Is This Answer Correct ? | 0 Yes | 0 No |
Explain Trouble shooting Splunk errors in splunk?
Which app ships with splunk enterprise?
How to reset splunk admin password?
Which command is used to the “filtering results” category- explain?
Where to create knowledge objects, dashboards, and reports?
Where does Splunk default configuration file located?
What is the Splunk latest version?
Where does splunk default configuration is stored?
What are important configuration files in Splunk?
State the difference between stats and event stats commands?
What is the use of license master in splunk?
What is the use of db connect in splunk?