Getting Data In

How do I remove a host from splunk, i want to delete a server that is forwarding entirely

sfunk
New Member

How do I remove a host from splunk, i want to delete a server that is forwarding entirely

Tags (2)
0 Karma

Ayn
Legend

First of all, stop the forwarder so that it doesn't send more events.

Secondly, delete the events. Then, this answer might be of interest to you. http://splunk-base.splunk.com/answers/1630/how-do-i-delete-all-references-of-a-host-so-it-stops-show...

sfunk
New Member

Attached is a screenshot, the host I want to remove is CBT-HD

0 Karma

sfunk
New Member

Please bare with me I'm a splunk rookie, I currently have a Windows server with a forwarder installed on it sending data to my spunk server, I just want to remove the server that is forwarding data to splunk from the host list in splunk itself, I wish there was a easy was to just hit delete etc in the host list, is there a specific cmd I need to run and if so how and from where? Thanks

0 Karma

Ayn
Legend

It's hard to give a meaningful answer with so little detail in your question. Please take some time to describe your issue more accurately. What is the current situation, what is the desired situation?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...