Getting Data In

Where does config file goes for Automatic lookups

rashi83
Path Finder

Hi , I want to delete few Automatic lookups from server as it doesnt give me option of deleting it from GUI. Even though I have admin access to the env -

Can someone please guide

alt text

Tags (1)
0 Karma

codebuilder
Influencer

Delete the lookup file(s) from the SHC deployer and push out a new bundle.
That is the only way to delete them from a search head cluster, and is likely the reason you are not able to do so from the UI.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

rashi83
Path Finder

Lookup has already been deleted . Issue is I cant delete the Automatic lookup definition.

0 Karma

codebuilder
Influencer

I'm guessing you have a dangling props.conf in a local folder somewhere (either system or user).
The deployer does not remove local files when you push a new bundle.

Use the following command to help find it:

/opt/splunk/splunk cmd btool props list --debug

Or use 'find' or 'locate' via CLI:

updatedb; locate props.conf
or
find /opt/splunk -name props.conf
----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

rashi83
Path Finder

this needs to be done on deployer or SH members?

0 Karma

codebuilder
Influencer

For local files you'll have to delete them manually on each search head.
But for clustered search heads, don't cycle Splunk manually, use the UI to cycle the cluster.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

rashi83
Path Finder

@codebuilder - I am seeing those lookup defn in default folder on SH members. Is it safe to just delete them from all members or should I push new deployment from deployer?

0 Karma

codebuilder
Influencer

No, do not delete them manually if they are in the default folder on the search heads, only if you find them in a local directory.

If they are in the default dir only, then you'll need to push a new bundle from the deployer. Be sure to delete the files on the deployer in both default and local folders under your app/TA before pushing it out. Any files under local on the deployer are merged into default and pushed to the search heads there.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

codebuilder
Influencer

Delete the file, or the relevant stanzas, then cycle Splunk.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

vnravikumar
Champion
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...