All Apps and Add-ons

How to remove a filer from Splunk for Splunk App for NetApp Data ONTAP?

krhorer
Engager

What is the proper way to remove a filer from Splunk? In most cases, this would be because it is decommissioned/replaced and one would want to keep the data for historical purposes. In my case, I changed the ONTAP Collection Configuration target name when I transitioned from evaluating the Splunk App for NetApp Data ONTAP to actually using it, so now I have a filer that shows up twice. I would like to either merge or delete the data from the evaluation period so the filer doesn't show up twice in the dashboard, etc. Using Splunk 6.1.3 with the ONTAP app 2.0.1.

I followed the directions in the documentation but both targets still show up in the dashboard.



Deleting a server (filer) removes it from your Splunk environment. You will no longer collect data from this machine. When you add or remove a filer from your environment you must stop and restart the scheduler.

To delete a server:


  • On the Collection Configuration dashboard, in the ONTAP Collection Configuration panel, select the server from the list of target machines. The Edit ONTAP Collection dialog is displayed.
  • Click Delete Server.
  • Confirm that you want to delete the filer, then click Save.
  • The filer is removed as a data source and it is removed from the list of target machines in the dashboard.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, I think that just alters the future collection behavior, and to delete the old data you'd need to use | delete in a search interface.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...