<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unable to delete data source in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217408#M163</link>
    <description>&lt;P&gt;I think i've done that but still get the same error message. How can i double check that the variable is set properly?&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jan 2016 17:53:03 GMT</pubDate>
    <dc:creator>yschiff</dc:creator>
    <dc:date>2016-01-07T17:53:03Z</dc:date>
    <item>
      <title>unable to delete data source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217402#M157</link>
      <description>&lt;P&gt;I am getting an error when trying to delete a data source: "Error occurred attempting to remove 10.0.0.81, 10.0.0.82, 172.16.1.18:9997: In handler 'raw': Malformed IP address: 10.0.0.81, 10.0.0.82, 172.16.1.18:9997."&lt;/P&gt;

&lt;P&gt;I have seen other post about this same issue and tried to follow the suggestions of deleting the corrupt entry in the inputs.conf file, however, I'm unable to locate the correct file. I have Splunk Light installed on a Win 10 x64 box and i'm looking through the C:\Program Files\Splunk\etc\system\default folder. The inputs.conf file found in that folder doesn't contain anything related to the data source i want to delete. i searched the entire Splunk folder for "9997" and nothing came back. is there somewhere else I should be looking?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 16:31:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217402#M157</guid>
      <dc:creator>yschiff</dc:creator>
      <dc:date>2016-01-07T16:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete data source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217403#M158</link>
      <description>&lt;P&gt;Please run this command to get the running config:&lt;BR /&gt;
    ./bin/splunk btool inputs list --debug&lt;BR /&gt;
You can then search the output for the bad stanza.  By adding --debug to the end of the command, Splunk will print the path to the config file that the line came from.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 17:28:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217403#M158</guid>
      <dc:creator>jchampagne_splu</dc:creator>
      <dc:date>2016-01-07T17:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete data source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217404#M159</link>
      <description>&lt;P&gt;If you want to stop indexing data from a source, remove it from inputs.conf but it does not delete data which is already indexed.&lt;/P&gt;

&lt;P&gt;inputs.conf can be located in &lt;EM&gt;etc/system/default&lt;/EM&gt;  OR &lt;EM&gt;/etc/system/local&lt;/EM&gt; in the main installation or under apps if you have installed one&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 17:31:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217404#M159</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2016-01-07T17:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete data source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217405#M160</link>
      <description>&lt;P&gt;This is what i got:&lt;BR /&gt;
C:\Program Files\Splunk\bin&amp;gt;btool inputs list --debug&lt;BR /&gt;
SPLUNK_HOME must be set.  Stopping.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 17:38:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217405#M160</guid>
      <dc:creator>yschiff</dc:creator>
      <dc:date>2016-01-07T17:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete data source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217406#M161</link>
      <description>&lt;P&gt;the inputs.conf in both the /default and /local folders do not contain information about the data source I created.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 17:40:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217406#M161</guid>
      <dc:creator>yschiff</dc:creator>
      <dc:date>2016-01-07T17:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete data source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217407#M162</link>
      <description>&lt;P&gt;Ok, you'll need to create a Windows environmental variable for $SPLUNK_HOME.  Please set the SPLUNK_HOME variable to C:\Program Files\Splunk&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:19:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217407#M162</guid>
      <dc:creator>jchampagne_splu</dc:creator>
      <dc:date>2020-09-29T08:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete data source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217408#M163</link>
      <description>&lt;P&gt;I think i've done that but still get the same error message. How can i double check that the variable is set properly?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 17:53:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217408#M163</guid>
      <dc:creator>yschiff</dc:creator>
      <dc:date>2016-01-07T17:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete data source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217409#M164</link>
      <description>&lt;P&gt;From the command prompt, type "set", you should see the environmental variable listed.&lt;BR /&gt;
If you don't see it, follow these instructions to create one: &lt;A href="https://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/sysdm_advancd_environmnt_addchange_variable.mspx?mfr=true"&gt;https://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/sysdm_advancd_environmnt_addchange_variable.mspx?mfr=true&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 17:55:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217409#M164</guid>
      <dc:creator>jchampagne_splu</dc:creator>
      <dc:date>2016-01-07T17:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete data source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217410#M165</link>
      <description>&lt;P&gt;Thank you! That did it. After setting the environmental variable i was able to run the btool utility to see which config file contained the malformed settings. I then deleted the malformed stanza and that removed it from my data inputs. FYI, i found the inputs.config file in C:\Program Files\Splunk\etc\apps\search\local&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 18:08:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217410#M165</guid>
      <dc:creator>yschiff</dc:creator>
      <dc:date>2016-01-07T18:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete data source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217411#M166</link>
      <description>&lt;P&gt;Thats great to hear.  As renjith.nair mentioned below, this will only stop new data from coming in.  If you want to delete the old data, you can run a search to pull back the old data and then add | delete to the end of the search.&lt;/P&gt;

&lt;P&gt;A couple of things to note about the delete command, by default you won't have the capability to run the command, you'll need to add this to your role under settings&amp;gt;access controls&lt;/P&gt;

&lt;P&gt;The delete command also doesn't actually delete the data on disk, it just marks it as deleted so Splunk won't include the data in your results.  It won't actually get delete until the underlying bucket rolls off.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.2/SearchReference/Delete"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.2/SearchReference/Delete&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 18:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217411#M166</guid>
      <dc:creator>jchampagne_splu</dc:creator>
      <dc:date>2016-01-07T18:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: unable to delete data source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217412#M167</link>
      <description>&lt;P&gt;Thanks for that tip. I don't need to delete anything because the data source was never actually working, hence why i wanted to remove it.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 18:28:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/unable-to-delete-data-source/m-p/217412#M167</guid>
      <dc:creator>yschiff</dc:creator>
      <dc:date>2016-01-07T18:28:11Z</dc:date>
    </item>
  </channel>
</rss>

