All Apps and Add-ons

How do I delete a data model or a data table built with the new Splunk Datasets Add-on?

wcooper003
Communicator

I've been playing around with the new datasets add-on - it's very slick, well done. Now I want to delete some of the testing tables I created, but there isn't a Delete option in the Data Model Manager page (I'm an admin). I realized I don't have a Delete option for either data models or tables (from the new datasets add-on) in the manager page. How do I delete these?

Reading the documentation for deleting data models, it appears I should have the ability to from this manager page (http://docs.splunk.com/Documentation/Splunk/6.5.0/Knowledge/Managedatamodels#Delete_a_data_model):

"Delete a data model
You can delete a data model from the Data Model management page or the Data Model Editor. Just click Edit and select Delete.
Note: If your role grants you the ability to create data models, it should grant you the ability to delete them as well. For more information about this see Enable roles to create data models."

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi wcooper003,
To delete your Datamodel you have to do:

if your DataModel is shared al App level:

  • go at $SPLUNK_HOME/etc/apps/yourapp/local/
  • edit datamodels.conf
  • delete your DataModel stanza
  • go at $SPLUNK_HOME/etc/apps/yourapp/local/data/model
  • delete your DataModel.json file
  • restart Splunk

if your DataModel is shared al Private level:

  • go at $SPLUNK_HOME/etc/users/youruser/yourapp/local/
  • edit datamodels.conf
  • delete your DataModel stanza
  • go at $SPLUNK_HOME/etc/users/youruser/yourapp/local/data/model
  • delete your DataModel.json file
  • restart Splunk

Bye.
Giuseppe

View solution in original post

arobbins_splunk
Splunk Employee
Splunk Employee

You should also be able to delete within the UI.

On the datasets listing page, there should be a "Manage" item in each row.

For a Table dataset created with the new Table UI:
1) select Manage for the dataset you want to delete
2) select "Delete" from the menu that opens up under Manage

For a Data Model:
1) select Manage for the Data Model you want to delete
2) select "Edit Data Model" from the menu that opens up under Manage (this will take you to the editing page for that Data Model)
3) in the upper-right portion of screen, you should see the options: Edit|Download|Pivot|Documentation
4) select Edit, which will result in a little menu opening up
5) select Delete from the Edit menu
and then on the Data Model's editing page, under the "Edit" menu in the upper-right (just under the Settings and Activity part of the Splunkbar) there should be

wcooper003
Communicator

Ok i see where I was confused.

There isn't a 'Manage' option under Actions from the Data Model Manager page (Settings -> Data Models):
https://xxxxxxx/en-US/manager/search/data_model_manager

But there is a 'Manage' option under Actions from the datasets page:
https://xxxxxxxxx/en-US/app/search/datasets

So you just need to know which page to go to for the Manage -> Delete.

Thanks

mattness
Splunk Employee
Splunk Employee

This method is documented more clearly here: http://docs.splunk.com/Documentation/Splunk/6.5.0/Knowledge/Workwithdatasets#Delete_datasets

I'll update the documentation so that the two sets of instructions correspond with each other better.

Matt Ness,
Splunk Documentation

gcusello
SplunkTrust
SplunkTrust

Hi wcooper003,
To delete your Datamodel you have to do:

if your DataModel is shared al App level:

  • go at $SPLUNK_HOME/etc/apps/yourapp/local/
  • edit datamodels.conf
  • delete your DataModel stanza
  • go at $SPLUNK_HOME/etc/apps/yourapp/local/data/model
  • delete your DataModel.json file
  • restart Splunk

if your DataModel is shared al Private level:

  • go at $SPLUNK_HOME/etc/users/youruser/yourapp/local/
  • edit datamodels.conf
  • delete your DataModel stanza
  • go at $SPLUNK_HOME/etc/users/youruser/yourapp/local/data/model
  • delete your DataModel.json file
  • restart Splunk

Bye.
Giuseppe

wcooper003
Communicator

Thanks for the detail.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...