Hi, still learning Splunk and.....need to know..
How to delete an "source type" that is tied to indexed data. I accidentally added the source type and now want to correct it. I am using Ver. 5.0.4.
Can help?
Thanks!
You can handle this in a few ways:
1) Delete the data (must have the can_delete capability) using | delete
2) Alias the sourcetype - add this to props.conf
[old_sourcetype]
rename = new_sourcetype]
3) re-index the data with the correct sourcetype.
Thanks for asking.
I deleted the old sourcetype and re-indexed (and not stealing the credit....your answer helped me too.).
Thanks again!
Did this help you?
Hi,
Try with this command in the search: sourcetype=
Before you need to check that your user have permissions to do this.
Cheers,
Thanks....this was helpful.