Hi , I want to delete few Automatic lookups from server as it doesnt give me option of deleting it from GUI. Even though I have admin access to the env -
Can someone please guide
Delete the lookup file(s) from the SHC deployer and push out a new bundle.
That is the only way to delete them from a search head cluster, and is likely the reason you are not able to do so from the UI.
Lookup has already been deleted . Issue is I cant delete the Automatic lookup definition.
I'm guessing you have a dangling props.conf in a local folder somewhere (either system or user).
The deployer does not remove local files when you push a new bundle.
Use the following command to help find it:
/opt/splunk/splunk cmd btool props list --debug
Or use 'find' or 'locate' via CLI:
updatedb; locate props.conf
or
find /opt/splunk -name props.conf
this needs to be done on deployer or SH members?
For local files you'll have to delete them manually on each search head.
But for clustered search heads, don't cycle Splunk manually, use the UI to cycle the cluster.
@codebuilder - I am seeing those lookup defn in default folder on SH members. Is it safe to just delete them from all members or should I push new deployment from deployer?
No, do not delete them manually if they are in the default folder on the search heads, only if you find them in a local directory.
If they are in the default dir only, then you'll need to push a new bundle from the deployer. Be sure to delete the files on the deployer in both default and local folders under your app/TA before pushing it out. Any files under local on the deployer are merged into default and pushed to the search heads there.
Delete the file, or the relevant stanzas, then cycle Splunk.