<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with sources in search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-sources-in-search/m-p/93350#M24034</link>
    <description>&lt;P&gt;Thank you for the suggestion! I would post it as a seperate question. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Jul 2012 05:25:59 GMT</pubDate>
    <dc:creator>jaterlwj</dc:creator>
    <dc:date>2012-07-09T05:25:59Z</dc:date>
    <item>
      <title>Problem with sources in search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-sources-in-search/m-p/93346#M24030</link>
      <description>&lt;P&gt;I know this may sound retarded, but I'm really new to Splunk so any help would be appreciated! I have been wondering. In the search app , how can I add/remove data from the "sources"? &lt;/P&gt;

&lt;P&gt;I have removed all data inputs using the manager but the data is still there. I have tried adding new data inputs as well but to no avail. &lt;/P&gt;

&lt;P&gt;The data source only references the first data that I fed it when I installed Splunk. Can any one be kind enough to help me?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2012 01:52:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-sources-in-search/m-p/93346#M24030</guid>
      <dc:creator>jaterlwj</dc:creator>
      <dc:date>2012-07-09T01:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with sources in search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-sources-in-search/m-p/93347#M24031</link>
      <description>&lt;P&gt;Mostly, you can't. Once the data is in, it's an administrative operation to remove it, and only with heavy restrictions.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2012 02:50:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-sources-in-search/m-p/93347#M24031</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-07-09T02:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with sources in search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-sources-in-search/m-p/93348#M24032</link>
      <description>&lt;P&gt;Ahh. I managed to clear the indexes using the CLI clean command! Thank you. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;On a side note, I have tested and realized that when monitoring a file with let's say 24 rows with the option "Continuously index data from a file or directory this Splunk instance can access".&lt;/P&gt;

&lt;P&gt;I noticed that when I add a new row and refreshes. There are now 49 rows. The older 24 records are being duplicated. Is there any option to stop duplicate rows?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2012 03:07:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-sources-in-search/m-p/93348#M24032</guid>
      <dc:creator>jaterlwj</dc:creator>
      <dc:date>2012-07-09T03:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with sources in search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-sources-in-search/m-p/93349#M24033</link>
      <description>&lt;P&gt;That should be asked as a separate question with more details - generally if you just add a record to a source Splunk will not reindex everything (if it did, your license usage would grow exponentially), so there's something in your specific situation that makes it behave this way.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2012 05:18:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-sources-in-search/m-p/93349#M24033</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-07-09T05:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with sources in search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-sources-in-search/m-p/93350#M24034</link>
      <description>&lt;P&gt;Thank you for the suggestion! I would post it as a seperate question. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2012 05:25:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-sources-in-search/m-p/93350#M24034</guid>
      <dc:creator>jaterlwj</dc:creator>
      <dc:date>2012-07-09T05:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with sources in search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problem-with-sources-in-search/m-p/93351#M24035</link>
      <description>&lt;P&gt;I am facing the same problem! I can't find my newly added data input. It can't be accessed through Search! Why? Could anyone help me with this?&lt;/P&gt;

&lt;P&gt;P.S. I am new to Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2013 10:52:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problem-with-sources-in-search/m-p/93351#M24035</guid>
      <dc:creator>anujamk</dc:creator>
      <dc:date>2013-02-26T10:52:37Z</dc:date>
    </item>
  </channel>
</rss>

