Getting Data In

Can't delete a saved search - Do I have to try it with REST or is there another way?

cpetterborg
SplunkTrust
SplunkTrust

I have some searches that in the Settings -> Searches, reports and alerts it doesn't have a delete link. I've tried googling and other searches to find a way to delete these searches without coming up with an answer, other than trying to use the REST API to delete them, but I don't want to go there unless I have to. Here is what I see:

alt text

Note that there are two searches that don't have a Delete link. I'm logged in as myself, the owner of the search, and as admin, but none of these has a Delete link. Is there some command line way to do this? We have a search head cluster, so I can't just go delete it from the file without causing other issues.

Any ideas how to delete these searches without jumping through the REST API hoops?

Thanks!

  • - As additional information, the search cannot be reverted back to a private search from one that it available within the app.

the_wolverine
Champion

I've seen this issue before and I believe its a bug. You could aways delete the saved search directly from savedsearches.conf. Another thing to try is to toggle the app context dropdown (all apps) to see if it will give you access to delete button.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Thanks for the suggestions. We had this same sort of problem back on 4.3.2, but when we upgraded to 6.0 it fixed those problems. If this is a bug, it's still in there, or was reintroduced with on the the updates since. We are currently on 6.4.1.

Tried the global (all apps) permission, that that didn't do it.

The problem with removing it from savedsearches.conf is that we are in a search head cluster, and deleting it from one search head doesn't delete it from any other, and it can cause problems if you delete it from each search head manually (so I've seen anyway). Splunk docs say to remove something from the SHC that you have to do it through the UI, or command line (splunk cmd ...) in order to maintain consistency across the cluster.

If I can't get a good way, I'll TRY using the REST API.

Thanks again.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...