<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Purging Extra Source Types &amp; related data? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Purging-Extra-Source-Types-related-data/m-p/47087#M11244</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have a couple issues.  First off, my Splunk server blue screened (yay for Windows!) and now I have a source &amp;amp; sourcetype called recovery-padding-1, recovery-padding-2, recovery-padding-3, recovery-padding-4, &amp;amp; recovery-padding-5.  &lt;/P&gt;

&lt;P&gt;Also, for some odd reason, I have two sets of sources for my Windows Event logs,&lt;/P&gt;

&lt;P&gt;WinEventLog:Security &amp;amp; wineventlog:security
WinEventLog:System &amp;amp; wineventlog:system&lt;/P&gt;

&lt;P&gt;All new data is being written to the capitalized, for some reason the others showed up some day, have a few hundred thousand events, and when searching, it does not matter (everything shows as WinEventLog:Security regardless of search for WinEventLog:Security or wineventlog:security). &lt;/P&gt;

&lt;P&gt;However, all these extra sources &amp;amp; sourcetypes are very annoying on the search summary screen.  &lt;/P&gt;

&lt;P&gt;Also, I have a host with 3 events because my transforms which modifies the host field didn't work right.&lt;/P&gt;

&lt;P&gt;Is there anyway to rid myself of all this extra stuff???&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Kevin&lt;/P&gt;</description>
    <pubDate>Fri, 10 Sep 2010 01:44:07 GMT</pubDate>
    <dc:creator>kholleran</dc:creator>
    <dc:date>2010-09-10T01:44:07Z</dc:date>
    <item>
      <title>Purging Extra Source Types &amp; related data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Purging-Extra-Source-Types-related-data/m-p/47087#M11244</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have a couple issues.  First off, my Splunk server blue screened (yay for Windows!) and now I have a source &amp;amp; sourcetype called recovery-padding-1, recovery-padding-2, recovery-padding-3, recovery-padding-4, &amp;amp; recovery-padding-5.  &lt;/P&gt;

&lt;P&gt;Also, for some odd reason, I have two sets of sources for my Windows Event logs,&lt;/P&gt;

&lt;P&gt;WinEventLog:Security &amp;amp; wineventlog:security
WinEventLog:System &amp;amp; wineventlog:system&lt;/P&gt;

&lt;P&gt;All new data is being written to the capitalized, for some reason the others showed up some day, have a few hundred thousand events, and when searching, it does not matter (everything shows as WinEventLog:Security regardless of search for WinEventLog:Security or wineventlog:security). &lt;/P&gt;

&lt;P&gt;However, all these extra sources &amp;amp; sourcetypes are very annoying on the search summary screen.  &lt;/P&gt;

&lt;P&gt;Also, I have a host with 3 events because my transforms which modifies the host field didn't work right.&lt;/P&gt;

&lt;P&gt;Is there anyway to rid myself of all this extra stuff???&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2010 01:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Purging-Extra-Source-Types-related-data/m-p/47087#M11244</guid>
      <dc:creator>kholleran</dc:creator>
      <dc:date>2010-09-10T01:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Purging Extra Source Types &amp; related data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Purging-Extra-Source-Types-related-data/m-p/47088#M11245</link>
      <description>&lt;P&gt;If you have a search that is returning ONLY data you wish to never see again, you may mark it as deleted by &lt;A href="http://answers.splunk.com/questions/1484/how-do-i-delete-events" rel="nofollow"&gt;piping it to the delete command&lt;/A&gt; in the Search app.&lt;/P&gt;

&lt;P&gt;By default, no user has this capability so it will have to be added via &lt;EM&gt;Access Controls&lt;/EM&gt; in the Manager (under Roles).  Be very careful when using the delete command &lt;STRONG&gt;and&lt;/STRONG&gt; it is a good idea to remove the capability as soon as you are finished with it.  &lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2010 01:54:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Purging-Extra-Source-Types-related-data/m-p/47088#M11245</guid>
      <dc:creator>bwooden</dc:creator>
      <dc:date>2010-09-10T01:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Purging Extra Source Types &amp; related data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Purging-Extra-Source-Types-related-data/m-p/47089#M11246</link>
      <description>&lt;P&gt;The padding entries exist as placeholders for what are essentially missing information problems that can occur with hard crashes.&lt;/P&gt;

&lt;P&gt;The padding entries should not show up in the search summary screen.  This was a problem that I believe was fixed in a relatively recent release.  Are you running 4.1.3 or earlier?&lt;/P&gt;

&lt;P&gt;You can hide arbitrary events (such as your mishandled transform events) with the |delete command (USE WITH CARE!) &lt;A href="http://www.splunk.com/base/Documentation/4.1.5/SearchReference/Delete" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.5/SearchReference/Delete&lt;/A&gt;  &lt;/P&gt;

&lt;P&gt;If you hide all the events with the accidental host, it will vanish from the summary at a later point when the global metadata is rebuilt.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2010 02:02:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Purging-Extra-Source-Types-related-data/m-p/47089#M11246</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-09-10T02:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Purging Extra Source Types &amp; related data?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Purging-Extra-Source-Types-related-data/m-p/47090#M11247</link>
      <description>&lt;P&gt;I am running 4.1.3.  I will look into running an upgrade.&lt;/P&gt;

&lt;P&gt;thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2010 22:32:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Purging-Extra-Source-Types-related-data/m-p/47090#M11247</guid>
      <dc:creator>kholleran</dc:creator>
      <dc:date>2010-09-24T22:32:43Z</dc:date>
    </item>
  </channel>
</rss>

