All Apps and Add-ons

How to remove a filer from Splunk for Splunk App for NetApp Data ONTAP?

krhorer
Engager

What is the proper way to remove a filer from Splunk? In most cases, this would be because it is decommissioned/replaced and one would want to keep the data for historical purposes. In my case, I changed the ONTAP Collection Configuration target name when I transitioned from evaluating the Splunk App for NetApp Data ONTAP to actually using it, so now I have a filer that shows up twice. I would like to either merge or delete the data from the evaluation period so the filer doesn't show up twice in the dashboard, etc. Using Splunk 6.1.3 with the ONTAP app 2.0.1.

I followed the directions in the documentation but both targets still show up in the dashboard.



Deleting a server (filer) removes it from your Splunk environment. You will no longer collect data from this machine. When you add or remove a filer from your environment you must stop and restart the scheduler.

To delete a server:


  • On the Collection Configuration dashboard, in the ONTAP Collection Configuration panel, select the server from the list of target machines. The Edit ONTAP Collection dialog is displayed.
  • Click Delete Server.
  • Confirm that you want to delete the filer, then click Save.
  • The filer is removed as a data source and it is removed from the list of target machines in the dashboard.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, I think that just alters the future collection behavior, and to delete the old data you'd need to use | delete in a search interface.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...