Answer Posted / Javed Siddique
To prevent events from being indexed by Splunk, you can create a forwarder configuration file with a 'disableLocalInput' attribute set to 'true'. Additionally, you can also use the 'inhibit-local-inputs.conf' file on the forwarder for similar purposes.
| Is This Answer Correct ? | 0 Yes | 0 No |
Post New Answer View All Answers