How to prevent events from being indexed by splunk?
Answer / Javed Siddique
To prevent events from being indexed by Splunk, you can create a forwarder configuration file with a 'disableLocalInput' attribute set to 'true'. Additionally, you can also use the 'inhibit-local-inputs.conf' file on the forwarder for similar purposes.
| Is This Answer Correct ? | 0 Yes | 0 No |
What are the types of alerts in splunk?
What are the unique benefits of getting data into a splunk instance via forwarders?
How to locate the place where default splunk configuration is stored?
Why Splunk is used for analysing machine data?
List out common ports used by splunk?
How data ages in splunk?
What is the difference between splunk sdk and splunk framework?
What is dispatch directory?
How many roles are there in splunk?
How to turn down a peer without affecting any other peer of cluster?
Which command is used to the “filtering results” category- explain?
What are types of splunk licenses?