unfortunately, | delete will not actually make the sources not show up. A bug makes it so the sources will still show up, but with a count of 0. (in the summary dashboard, that is)
Again, it all depends on what you are trying to do, just like Bwooden said...
Put the [| delete] after your specific source [source="zzzzzz" | delete]
But you need to add can_delete role to your account before do above process
Hi .. where to use this command, i have tried in search but it didnt work out
Oh - I found it here: http://www.splunk.com/base/Documentation/latest/Admin/RemovedatafromSplunk
I am using splunk 5.0.2 and the above link does not apply for the latest version. How can I delete a source or sourcetype from the splunk server? The reason I want to delete the source/sourcetype is to reorganize my search dashboard. Currently I have configured the splunk universal forwarder to monitor glassfish logs (server.log file). With this configuration I see all the server.log* files transferred to the splunk server. I want them to be grouped them into one logical group since I have multiple instances and clusters configured on glassfish. How do I do that?
thx fribert ^___^
I have the same question! I cannot find a way to get rid of them...
There are several options. The best approach depends on what you are ultimately trying to accomplish by removing them. Please add more detail.