Splunk Cloud Platform

Can we delete user created sourcetypes on Splunk Cloud?

Splunker96
Builder

Hello,

Is it possible to delete user created sourcetypes on splunk cloud, i checked under all configurations and sourcetypes options but didn't found anything.

Anyone has an idea? I guess we need to open a case to splunk support for deletion?

 

 

Thanks

Labels (1)
0 Karma

Splunker96
Builder

Hey @richgalloway 

I am on Splunk cloud and I don't see delete option under actions column, I can only see Edit and Clone.

 

Thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I use Splunk Cloud as well and sometime see a "Delete" option.  I don't know what makes it available.

The only other solution I can offer is to upload a new version of the app that contains that sourcetype, but without the sourcetype.

Either way, removing the sourcetype means events with that sourcetype may not be processed properly.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Splunker96
Builder

@richgalloway Thank you for sharing the instructions.

Meanwhile, I will open a case to Splunk support to see if they enable delete option atleast for sc_admin role.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you should be able to delete custom sourcetypes.  Go to Settings->Sourcetypes and the Actions column will contain "Delete" for those sourcetypes you can delete.  I don't know how Splunk decides which sourcetypes you can and cannot delete, however.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...