Splunk Cloud Platform

Can we delete user created sourcetypes on Splunk Cloud?

Roy_9
Motivator

Hello,

Is it possible to delete user created sourcetypes on splunk cloud, i checked under all configurations and sourcetypes options but didn't found anything.

Anyone has an idea? I guess we need to open a case to splunk support for deletion?

 

 

Thanks

Labels (1)
0 Karma

Roy_9
Motivator

Hey @richgalloway 

I am on Splunk cloud and I don't see delete option under actions column, I can only see Edit and Clone.

 

Thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I use Splunk Cloud as well and sometime see a "Delete" option.  I don't know what makes it available.

The only other solution I can offer is to upload a new version of the app that contains that sourcetype, but without the sourcetype.

Either way, removing the sourcetype means events with that sourcetype may not be processed properly.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Roy_9
Motivator

@richgalloway Thank you for sharing the instructions.

Meanwhile, I will open a case to Splunk support to see if they enable delete option atleast for sc_admin role.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you should be able to delete custom sourcetypes.  Go to Settings->Sourcetypes and the Actions column will contain "Delete" for those sourcetypes you can delete.  I don't know how Splunk decides which sourcetypes you can and cannot delete, however.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...