Installation

Observations/Question Recently Installed Splunk

osamamansoor
New Member

Hi All,

i just recently installed splunk enterprise and having following questions.

1.How can i delete previously indexed hosts
2.How can i edited/deleted sources type for particular hosts

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Indexed data isn't for changing, so you cannot fully delete data based on some host, or change the sourcetype value for some host.

You can empty an entire index, run this while splunk is stopped:$SPLUNK_HOME/bin/splunk clean eventdata -index yourindex
You can mark individual events as deleted without cleaning up space, append the delete command to a search to mark the results as deleted - your user needs the can_delete role to be allowed to.

To alleviate the impact of wrong indexing in the future, consider creating a sandbox index to first send data into, confirm its correct, and only then send data into your actual indexes.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...