Hi guys,
I configured my all-in-one Splunk instance to forward data to another SH by using an tcpout:9997 at outputs.conf. Then I removed the config file manually from Ubuntu command line.
However, I found data from my all-in-one Splunk box still forwarding to the other SH after reboot.
So I checked Forwarding and receiving setting from Web UI. I found the previous setting still there. Please see the attached screenshot for details.
![alt text][1]
[1]: /storage/temp/137176-tcpout.jpg
Is there a way to remove those two forward data configuration from either Web UI or CMD?
Could any one please help?
Cheers,
Vincent
↧