<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: remove source type in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29363#M5035</link>
    <description>&lt;P&gt;i try:&lt;/P&gt;

&lt;P&gt;index=audit.log | delete&lt;/P&gt;

&lt;P&gt;0 line deleted.&lt;/P&gt;

&lt;P&gt;Okay maybe this error is comming from another problem:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;i cant add to monitor and index a directory, for example /var/log/&lt;/LI&gt;
&lt;LI&gt;i add /var/log/samba/audit.log file to the data inputs. But it looks like the file is added but when i try to search i found nothing. Just when the file is not added to the data inputs and no index is generated.&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Wed, 18 Apr 2012 08:22:19 GMT</pubDate>
    <dc:creator>idekuld</dc:creator>
    <dc:date>2012-04-18T08:22:19Z</dc:date>
    <item>
      <title>remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29359#M5031</link>
      <description>&lt;P&gt;How is this possible?&lt;/P&gt;

&lt;H1&gt;./splunk help commands&lt;/H1&gt;

&lt;PRE&gt;&lt;CODE&gt;This page shows you the syntax and summary of the Splunk CLI commands.

Splunk CLI command syntax:

./splunk [command] [object] [-parameter &amp;lt;value&amp;gt;]...

* Some commands don't require an object or parameters.
* Some commands have a default parameter that can be specified by its
  value alone.

Commands and objects:

* A command is an action that you can perform.
* An object is something you perform an action on.

Supported commands and objects:

    [command]           [objects]

    add                 [exec|forward-server|index|licenser-pools|licenses|monitor|oneshot|
                        saved-search|search-server|tcp|udp|user]

    anonymize           source

    clean               [all|eventdata|globaldata|userdata]

    create              app

    diag                NONE

    disable             [app|boot-start|deploy-client|deploy-server|discoverable|
                        dist-search|index|listen|local-index|webserver|web-ssl]

    display             [app|boot-start|deploy-client|deploy-server|discoverable|
                        dist-search|index|jobs|listen|local-index]

    edit                [app|exec|forward-server|index|licenser-localslave|licenses|
                        licenser-groups|
                        monitor|saved-search|search-server|tcp|udp|user]

    enable              [app|deploy-client|deploy-server|discoverable|dist-search|
                        index|listen|local-index|boot-start|webserver|web-ssl]

    export,import       [eventdata|userdata]

    find                logs

    help                NONE

    list                [deploy-clients|exec|forward-server|index|licenser-groups|
                        licenser-localslave|licenser-messages|licenser-pools|licenser-slaves|
                        licenser-stacks|licenses|jobs|monitor|saved-search|search-server|
                        source|sourcetype|tcp|udp|user]

    login,logout        NONE

    package             app

    refresh             deploy-clients

    reload              [auth|deploy-server]

    remove              [app|exec|forward-server|jobs|licenser-pools|licenses|monitor|
                        saved-search|search-server|source|sourcetype|tcp|udp|user]

    search              NONE

    set                 [datastore-dir|deploy-poll|default-hostname|default-index|
                        minfreemb|servername|server-type|splunkd-port|web-port]

    show                [config|datastore-dir|deploy-poll|default-hostname|default-index|
                        jobs|minfreemb|servername|splunkd-port|web-port]

    spool               NONE

    start,stop,restart  [monitor|splunkd|splunkweb]

    status              [monitor|splunkd|splunkweb]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Syntax:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    None
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Objects:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    None
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Required Parameters:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    None
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Optional Parameters:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    None
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Examples:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    None
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Type "help [command]" to get help with parameters for a specific command.&lt;/P&gt;

&lt;P&gt;Complete documentation is available online at: &lt;A href="http://docs.splunk.com/Documentation"&gt;http://docs.splunk.com/Documentation&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;root@sphs1i-fileaudit01:/opt/splunk/bin# ./splunk remove sourcetype audit.log&lt;/P&gt;

&lt;P&gt;Command error: The subcommand 'sourcetype' is not valid for command 'remove'.&lt;BR /&gt;
root@sphs1i-fileaudit01:/opt/splunk/bin# ./splunk remove sourcetype&lt;/P&gt;

&lt;P&gt;Command error: The subcommand 'sourcetype' is not valid for command 'remove'.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2012 06:45:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29359#M5031</guid>
      <dc:creator>idekuld</dc:creator>
      <dc:date>2012-04-18T06:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29360#M5032</link>
      <description>&lt;P&gt;What do you mean by removing a sourcetype? A sourcetype is not something that exists by itself, rather it is a property that is assigned to events in the index.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2012 07:19:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29360#M5032</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-04-18T07:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29361#M5033</link>
      <description>&lt;P&gt;when i add data to Splunk then i can set a "source type"(new source type and apply an existing source type). After i created a lot of source type, i want to delete them because there are too many.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2012 07:26:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29361#M5033</guid>
      <dc:creator>idekuld</dc:creator>
      <dc:date>2012-04-18T07:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29362#M5034</link>
      <description>&lt;P&gt;You need to delete the events carrying those sourcetypes in that case. Check out the &lt;CODE&gt;delete&lt;/CODE&gt; operator: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Delete"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Delete&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2012 07:56:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29362#M5034</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-04-18T07:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29363#M5035</link>
      <description>&lt;P&gt;i try:&lt;/P&gt;

&lt;P&gt;index=audit.log | delete&lt;/P&gt;

&lt;P&gt;0 line deleted.&lt;/P&gt;

&lt;P&gt;Okay maybe this error is comming from another problem:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;i cant add to monitor and index a directory, for example /var/log/&lt;/LI&gt;
&lt;LI&gt;i add /var/log/samba/audit.log file to the data inputs. But it looks like the file is added but when i try to search i found nothing. Just when the file is not added to the data inputs and no index is generated.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 18 Apr 2012 08:22:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29363#M5035</guid>
      <dc:creator>idekuld</dc:creator>
      <dc:date>2012-04-18T08:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29364#M5036</link>
      <description>&lt;P&gt;index=audit.log? I think you're confusing terms here. Before you start deleting stuff, you really need to understand the concept of indexes, sources, sourcetypes etc.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2012 08:24:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29364#M5036</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-04-18T08:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29365#M5037</link>
      <description>&lt;P&gt;ok.&lt;/P&gt;

&lt;P&gt;I try to "add data" on the splunk web management page the /var/log/samba/audit.log file what is created by syslog to monitor. I added the file and nothing happend. i cant search in the file.&lt;/P&gt;

&lt;P&gt;Then i try to add a directory with the add data, on the web page. But I cant add any directory. Yes great feature.........&lt;/P&gt;

&lt;P&gt;You cant add a directory on the wb site, you can add it on th CLI. .... awesome....&lt;/P&gt;

&lt;P&gt;And the last other great feature, when the audit.log is in the /var/log/samba/ directory then splunk dont care this file, you must place this file to /var/log/.&lt;/P&gt;

&lt;P&gt;What do you think about this?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2012 09:29:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29365#M5037</guid>
      <dc:creator>idekuld</dc:creator>
      <dc:date>2012-04-18T09:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29366#M5038</link>
      <description>&lt;P&gt;As Ayn said, I think you have misunderstood a few basic concepts here.&lt;/P&gt;

&lt;P&gt;In response to the statement:&lt;/P&gt;

&lt;P&gt;"Then i try to add a directory with the add data, on the web page. But I cant add any directory. Yes great feature........."&lt;/P&gt;

&lt;P&gt;You are probably using the "preview" feature, this is new to Splunk as of 4.3, and yes it does only let you preview files, as directories can have many files, with many different formats... this feautre is more of an educational tool to help you understand linebreaking/timestamp recognition etc. You can "monitors" in directories if you use the old method...&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2012 09:37:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29366#M5038</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-04-18T09:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29367#M5039</link>
      <description>&lt;P&gt;(i.e. by using the "Skip preview" option!).&lt;/P&gt;

&lt;P&gt;You don't need to place files in /var/log/ for them to be monitored. As long as the user running Splunk (i.e. root) has "read" permissions on the file, Splunk can read it.&lt;/P&gt;

&lt;P&gt;I think you should read the docs, before jumping in head first, and the start again fresh....&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/User/AboutthisUserManual"&gt;http://docs.splunk.com/Documentation/Splunk/latest/User/AboutthisUserManual&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2012 09:41:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29367#M5039</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-04-18T09:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29368#M5040</link>
      <description>&lt;P&gt;And... yes... The preview feature, is a good feature (no sarcasm)... as it helps new users understand how to correctly input different types of files.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2012 09:43:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29368#M5040</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-04-18T09:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29369#M5041</link>
      <description>&lt;P&gt;"The preview feature, is a good feature" this will be a good feature when you solve the problem that the user not get what he except. (better documentation, teaching video, or something)&lt;/P&gt;

&lt;P&gt;Im new with splunk. Now it looks that what you get as web gui to configure is useless. I added the /var/log/samba/audit.log so many times. In the preview i see that everything is fine, but when is want to search in this file i get 0 result.&lt;/P&gt;

&lt;P&gt;After i run the command: /splunk add monitor /var/log/ i was to able to search in the log files. But /var/log/samba/audit.log was not in the list of files that can be searched. I must move this file to /var/log/audit.log, only after this was i able to find something in this file.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2012 10:47:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29369#M5041</guid>
      <dc:creator>idekuld</dc:creator>
      <dc:date>2012-04-18T10:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29370#M5042</link>
      <description>&lt;P&gt;Maybe the user that is running splunk doesn't have the correct right for the /var/log/samba directory?&lt;/P&gt;

&lt;P&gt;You're not giving us a lot of information, that's why nobody is helping.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2012 11:24:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29370#M5042</guid>
      <dc:creator>fbl_itcs</dc:creator>
      <dc:date>2012-09-27T11:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29371#M5043</link>
      <description>&lt;P&gt;My company recently rolled out Splunk for our Citrix XenApp 6.5 environment (&amp;gt;900 2008 R2 servers). So I'm running Splunk at home on my personal Debian server to get more exposure to this app...love it btw, keep up the good work. &lt;/P&gt;

&lt;P&gt;However, I have this question too on my personal Splunk 5.0.1, build 143156 Debian box...&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;"...After i created a lot of source type, i want to delete them because there are too many."&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Maybe the title of this question could more specifically read "remove (user created) sourcetype" as this is what I'm after as well.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;"You need to delete the events carrying those sourcetypes in that case."&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;This seems to be the way I've seen this question answered in other posts too (I'm done searching/reading, it's time to post), but this doesn't delete the sourcetype in the dropdown box chosen when creating an input file. &lt;/P&gt;

&lt;P&gt;Specifically, what is being asked is how are user created sourcetypes deleted/removed from the &lt;STRONG&gt;Set Source Type&lt;/STRONG&gt; popup box seen by doing the following: &lt;STRONG&gt;Manager&lt;/STRONG&gt; » &lt;STRONG&gt;Data inputs&lt;/STRONG&gt; » &lt;STRONG&gt;Files &amp;amp; directories&lt;/STRONG&gt; » &lt;STRONG&gt;Data preview&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Set Source Type&lt;/STRONG&gt; popup box. &lt;/P&gt;

&lt;P&gt;So far, I understand the steps to be...&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;verify your ID has the "delete_by_keyword" capability in &lt;STRONG&gt;Manager&lt;/STRONG&gt; » &lt;STRONG&gt;Access controls&lt;/STRONG&gt; » &lt;STRONG&gt;Roles&lt;/STRONG&gt; » &lt;STRONG&gt;yourID&lt;/STRONG&gt; &lt;/LI&gt;
&lt;LI&gt;run &lt;STRONG&gt;sourcetype=User_Created_Foo | Delete&lt;/STRONG&gt; in &lt;STRONG&gt;Splunk&lt;/STRONG&gt; » &lt;STRONG&gt;Search&lt;/STRONG&gt; to remove entries that have have the &lt;STRONG&gt;User_Created_Foo&lt;/STRONG&gt; sourcetype&lt;/LI&gt;
&lt;LI&gt;?&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Dear Splunk Ninja, please answer what task needs to be done to delete the User_Created_Foo indextype from the &lt;STRONG&gt;Set Source Type&lt;/STRONG&gt; popup box in step 3. &lt;/P&gt;

&lt;P&gt;Thank you very much!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:20:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29371#M5043</guid>
      <dc:creator>cyphertek</dc:creator>
      <dc:date>2020-09-28T14:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29372#M5044</link>
      <description>&lt;P&gt;Just a guess:&lt;/P&gt;

&lt;P&gt;Are those sourcetypes you want to delete mentioned in any props.conf/transforms.conf because you configured special treatment there? Take a look and delete any appearance of the sourcetypes in those files.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2013 18:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29372#M5044</guid>
      <dc:creator>fbl_itcs</dc:creator>
      <dc:date>2013-07-13T18:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29373#M5045</link>
      <description>&lt;P&gt;fbl_itcs,&lt;/P&gt;

&lt;P&gt;Thank you, that is the answer.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2013 19:54:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29373#M5045</guid>
      <dc:creator>cyphertek</dc:creator>
      <dc:date>2013-07-13T19:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: remove source type</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29374#M5046</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;All the created sourcetype was configured in "props.conf" file under "/etc/system/local". To reuse the sourcetype you previously use, you must delete its configuration first.&lt;/P&gt;

&lt;P&gt;Hope this helps!!&lt;/P&gt;</description>
      <pubDate>Wed, 03 Dec 2014 07:13:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/remove-source-type/m-p/29374#M5046</guid>
      <dc:creator>jhlopez</dc:creator>
      <dc:date>2014-12-03T07:13:27Z</dc:date>
    </item>
  </channel>
</rss>

