Brand new to Splunk. Installed the universal forwarder on a Windows Server and see the logs populating on my Splunk Light server. I want to re-configure the forwarder to not include performance monitoring (which I selected on install.)
Where is the conf file that I need to edit? I see documentation that points to conf files located here:
C:\Program Files\SplunkUniversalForwarder\etc\system\local
But I don't see any data relating to which logs and performance monitoring is being forwarded here.
↧