Hi guys,
I configured my all-in-one Splunk instance to forward data to another search head by using an tcpout:9997 at outputs.conf. Then I removed the config file manually from Ubuntu command line.
However, I found data from my all-in-one Splunk box still forwarding to the other SH after reboot.
So I checked Forwarding and receiving setting from Splunk Web. I found the previous setting still there. Please see the attached screenshot for details.
![alt text][1]
Is there a way to remove those two forward data configurations from either Splunk Web or CMD?
Could any one please help?
Cheers,
Vincent
[1]: /storage/temp/137177-137176-tcpout.jpg
↧