All Apps and Add-ons

How to delete a KV STORE lookup?

agentsofshield
Path Finder

I have write permissions on a KV Store lookup. When I try to press "delete" on the Lookup Editor app, it says "Lookup file could not be deleted". I'm not trying to delete information, I want to delete the whole lookup. How can I do this?

ro_mc
Path Finder

To delete the config for the collection, rather than the records within it, use:

curl -k -u admin:changeme -X DELETE https://<host>:8089/servicesNS/nobody/<app>/storage/collections/config/<collection>

Deleting the transform lookup configuration may still work, but this is the solution currently provided in the Splunk docs at https://dev.splunk.com/enterprise/docs/developapps/manageknowledge/kvstore/usetherestapitomanagekv/

0 Karma

ilyaresh
Path Finder

Hi,
Have you tried to send DELETE call to
https://{{sh_url}}:8089/servicesNS/nobody/{{sh_app_name}}/data/transforms/lookups/{{lookup_name}}
you might need to change nobody to specific user if the lookup is defined having user and not app level permission.

for example using curl

curl -X DELETE \
  https://{{sh_url}}:8089/servicesNS/nobody/{{sh_app_name}}/data/transforms/lookups/{{lookup_name}}

Regards,
ILYA

0 Karma

agentsofshield
Path Finder

I tried to use clean command, on the server it said "deleted" but Lookup Editor still claims the lookup exists.

The simple command "|outputlookup " won't help me because I want to delete the lookup table itself and not just the data.

0 Karma

vnravikumar
Champion

Hi

Try the following command

curl -k -u splunkadmin:splunkadmin --request DELETE https://localhost:8089/servicesNS/splunkadmin/search/data/transforms/lookups/lookuptest

Here
splunkadmin is the username/password
lookuptest is the definition name.
search is the app name

0 Karma

agentsofshield
Path Finder

Sorry, I tried and it says "curl: (35) TCP connection reset by peer" even after replacing the values you mentioned ever with different admin users.

Is there no way to use the GUI to delete?

0 Karma

vnravikumar
Champion

Try the above command and let me know.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...