Getting Data In

remove source type

idekuld
Explorer

How is this possible?

./splunk help commands

This page shows you the syntax and summary of the Splunk CLI commands.

Splunk CLI command syntax:

./splunk [command] [object] [-parameter <value>]...

* Some commands don't require an object or parameters.
* Some commands have a default parameter that can be specified by its
  value alone.

Commands and objects:

* A command is an action that you can perform.
* An object is something you perform an action on.

Supported commands and objects:

    [command]           [objects]

    add                 [exec|forward-server|index|licenser-pools|licenses|monitor|oneshot|
                        saved-search|search-server|tcp|udp|user]

    anonymize           source

    clean               [all|eventdata|globaldata|userdata]

    create              app

    diag                NONE

    disable             [app|boot-start|deploy-client|deploy-server|discoverable|
                        dist-search|index|listen|local-index|webserver|web-ssl]

    display             [app|boot-start|deploy-client|deploy-server|discoverable|
                        dist-search|index|jobs|listen|local-index]

    edit                [app|exec|forward-server|index|licenser-localslave|licenses|
                        licenser-groups|
                        monitor|saved-search|search-server|tcp|udp|user]

    enable              [app|deploy-client|deploy-server|discoverable|dist-search|
                        index|listen|local-index|boot-start|webserver|web-ssl]

    export,import       [eventdata|userdata]

    find                logs

    help                NONE

    list                [deploy-clients|exec|forward-server|index|licenser-groups|
                        licenser-localslave|licenser-messages|licenser-pools|licenser-slaves|
                        licenser-stacks|licenses|jobs|monitor|saved-search|search-server|
                        source|sourcetype|tcp|udp|user]

    login,logout        NONE

    package             app

    refresh             deploy-clients

    reload              [auth|deploy-server]

    remove              [app|exec|forward-server|jobs|licenser-pools|licenses|monitor|
                        saved-search|search-server|source|sourcetype|tcp|udp|user]

    search              NONE

    set                 [datastore-dir|deploy-poll|default-hostname|default-index|
                        minfreemb|servername|server-type|splunkd-port|web-port]

    show                [config|datastore-dir|deploy-poll|default-hostname|default-index|
                        jobs|minfreemb|servername|splunkd-port|web-port]

    spool               NONE

    start,stop,restart  [monitor|splunkd|splunkweb]

    status              [monitor|splunkd|splunkweb]

Syntax:

    None

Objects:

    None

Required Parameters:

    None

Optional Parameters:

    None

Examples:

    None

Type "help [command]" to get help with parameters for a specific command.

Complete documentation is available online at: http://docs.splunk.com/Documentation

root@sphs1i-fileaudit01:/opt/splunk/bin# ./splunk remove sourcetype audit.log

Command error: The subcommand 'sourcetype' is not valid for command 'remove'.
root@sphs1i-fileaudit01:/opt/splunk/bin# ./splunk remove sourcetype

Command error: The subcommand 'sourcetype' is not valid for command 'remove'.

Tags (3)
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...