This should be relatively simple but I cannot find discussion or documentation on it. I suspect that Splunk assumes if a UF is installed, the data is wanted. The problem is that there is a UF out of my control with a misconfigured index name. I would like blacklist it until the owner can fix it.
How would I blacklist a UF?
↧