Getting Data In

Deleting data inputs

sruthy
Explorer

Hi,
I am new to splunk and when i add datainputs i was not known about the timestamp issue and later i explored it. when i am trying to delete a data input and trying to reinsert it with proper format, i found that the earlier input is still indexed and when i am querying it , i am able to find it. i tried restarting splunk through splunk manager as well as windows services.(both splunkd and splunkweb)

Tags (1)
1 Solution

MHibbin
Influencer

Hi,

Welcome to the world of Splunk...

Without re-writing what has already been written... the following documentation would be helpful here.

http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/RemovedatafromSplunk

View solution in original post

MHibbin
Influencer

Hi,

Welcome to the world of Splunk...

Without re-writing what has already been written... the following documentation would be helpful here.

http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/RemovedatafromSplunk

Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...