Getting Data In

Delete custom sourcetype

millern4
Communicator

We were indexing some test data in our development environment in order to manipulate it to correct an issue we are having in production. We ended up having to make a few different sourcetypes (custom) that were done through the web and now I'm having issues deleting these.

I've looked on both the indexer and the search head to remove these and I'm unable to locate them anywhere (using the GUI) and also through the CLI. I've checked props.conf, transform.conf, and indexes.conf in addition to these message boards and Splunk Admin docs.

Is there a proper procedure to permanently delete custom sourcetypes, not this sourcetype=syslog_test | delete which seems to only remove it from future searches?

Any help is appreciated and also we worth noting we have a distributed environment so would I need to do this on the search head, indexers, or both?

Tags (1)
0 Karma
1 Solution

millern4
Communicator

so it appears these were created in props.conf on our indexer:

I then modified them in the local directory under:

/splunk/etc/system/local

to remove the custom sourcetype entries we added earlier in the morning, not sure why I missed them the first time around but all is once again well.

View solution in original post

0 Karma

millern4
Communicator

so it appears these were created in props.conf on our indexer:

I then modified them in the local directory under:

/splunk/etc/system/local

to remove the custom sourcetype entries we added earlier in the morning, not sure why I missed them the first time around but all is once again well.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Unlocking Data-In-Place Search Across Splunk and Snowflake  Enterprise data is increasingly distributed across ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...