Splunk Enterprise

How do I remove Sources?

howardhon
Engager

Hi ALL~

How do I remove Sources from my 'Sources Indexed'?

Thx.

Tags (1)

Genti
Splunk Employee
Splunk Employee

unfortunately, | delete will not actually make the sources not show up. A bug makes it so the sources will still show up, but with a count of 0. (in the summary dashboard, that is)

Again, it all depends on what you are trying to do, just like Bwooden said...

0 Karma

TheGU
Path Finder

Put the [| delete] after your specific source [source="zzzzzz" | delete]

But you need to add can_delete role to your account before do above process

0 Karma

rupesh_patil20
Path Finder

Hi .. where to use this command, i have tried in search but it didnt work out

0 Karma

fribert
Explorer

shahamit
Explorer

I am using splunk 5.0.2 and the above link does not apply for the latest version. How can I delete a source or sourcetype from the splunk server? The reason I want to delete the source/sourcetype is to reorganize my search dashboard. Currently I have configured the splunk universal forwarder to monitor glassfish logs (server.log file). With this configuration I see all the server.log* files transferred to the splunk server. I want them to be grouped them into one logical group since I have multiple instances and clusters configured on glassfish. How do I do that?

0 Karma

howardhon
Engager

thx fribert ^___^

0 Karma

fribert
Explorer

I have the same question! I cannot find a way to get rid of them...

0 Karma

bwooden
Splunk Employee
Splunk Employee

There are several options. The best approach depends on what you are ultimately trying to accomplish by removing them. Please add more detail.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...