All Apps and Add-ons

How to remove a filer from Splunk for Splunk App for NetApp Data ONTAP?

krhorer
Engager

What is the proper way to remove a filer from Splunk? In most cases, this would be because it is decommissioned/replaced and one would want to keep the data for historical purposes. In my case, I changed the ONTAP Collection Configuration target name when I transitioned from evaluating the Splunk App for NetApp Data ONTAP to actually using it, so now I have a filer that shows up twice. I would like to either merge or delete the data from the evaluation period so the filer doesn't show up twice in the dashboard, etc. Using Splunk 6.1.3 with the ONTAP app 2.0.1.

I followed the directions in the documentation but both targets still show up in the dashboard.



Deleting a server (filer) removes it from your Splunk environment. You will no longer collect data from this machine. When you add or remove a filer from your environment you must stop and restart the scheduler.

To delete a server:


  • On the Collection Configuration dashboard, in the ONTAP Collection Configuration panel, select the server from the list of target machines. The Edit ONTAP Collection dialog is displayed.
  • Click Delete Server.
  • Confirm that you want to delete the filer, then click Save.
  • The filer is removed as a data source and it is removed from the list of target machines in the dashboard.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, I think that just alters the future collection behavior, and to delete the old data you'd need to use | delete in a search interface.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...