Splunk Enterprise

How do I delete a TCP data source with a malformed IP address as the restricted host?

the4ndy
New Member

My first data source I wanted to catch all syslog from my servers on tcp port 514
i also decided to restrict the input accepted to my local subnet via the IP 10.0.13.0/24
as a result, when i go to remove the data source i get the following error.

Error occurred attempting to remove 10.0.13.0/24:514: In handler 'raw': Malformed IP address: 10.0.13.0/24:514.

is there a way to resolve this without re-installing the whole server?

EDIT: More clarification of "remove data source"

From the left hand sidebar menu, choose Data > Data Inputs
Then on the page that comes up, choose TCP
then it will show the TCP data inputs in a list and give the option on the right hand side to Clone or Delete
the delete option here fails and gives the error provided above

I apologize if I did not use proper names for the objects in Splunk, I am new to the software. Thanks.

Tags (1)
0 Karma

woodcock
Esteemed Legend

First of all, open a support case with splunk so that they will fix this bug. Go to the CLI on the Forwarder and find the inputs.conf file that has this entry. Delete the entire stanza (but copy all of the text so that you can include in your support case). Save the file, restart the splunk instance and it will be gone.

0 Karma

woodcock
Esteemed Legend

What do you mean by "remove the data source"? Give full description of what you are doing.

0 Karma

the4ndy
New Member

From the left hand sidebar menu, choose Data > Data Inputs
Then on the page that comes up, choose TCP
then it will show the TCP data inputs in a list and give the option on the right hand side to Clone or Delete
the delete option here fails and gives the error provided above

I apologize if I did not use proper names for the objects in Splunk, I am new to the software. Thanks.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...