What is the proper way to remove a filer from Splunk? In most cases, this would be because it is decommissioned/replaced and one would want to keep the data for historical purposes. In my case, I changed the ONTAP Collection Configuration target name when I transitioned from evaluating the Splunk App for NetApp Data ONTAP to actually using it, so now I have a filer that shows up twice. I would like to either merge or delete the data from the evaluation period so the filer doesn't show up twice in the dashboard, etc. Using Splunk 6.1.3 with the ONTAP app 2.0.1.
I followed the directions in the documentation but both targets still show up in the dashboard.
To delete a server:
Hi, I think that just alters the future collection behavior, and to delete the old data you'd need to use | delete in a search interface.