Splunk Enterprise

How do I remove Sources?

howardhon
Engager

Hi ALL~

How do I remove Sources from my 'Sources Indexed'?

Thx.

Tags (1)

Genti
Splunk Employee
Splunk Employee

unfortunately, | delete will not actually make the sources not show up. A bug makes it so the sources will still show up, but with a count of 0. (in the summary dashboard, that is)

Again, it all depends on what you are trying to do, just like Bwooden said...

0 Karma

TheGU
Path Finder

Put the [| delete] after your specific source [source="zzzzzz" | delete]

But you need to add can_delete role to your account before do above process

0 Karma

rupesh_patil20
Path Finder

Hi .. where to use this command, i have tried in search but it didnt work out

0 Karma

fribert
Explorer

shahamit
Explorer

I am using splunk 5.0.2 and the above link does not apply for the latest version. How can I delete a source or sourcetype from the splunk server? The reason I want to delete the source/sourcetype is to reorganize my search dashboard. Currently I have configured the splunk universal forwarder to monitor glassfish logs (server.log file). With this configuration I see all the server.log* files transferred to the splunk server. I want them to be grouped them into one logical group since I have multiple instances and clusters configured on glassfish. How do I do that?

0 Karma

howardhon
Engager

thx fribert ^___^

0 Karma

fribert
Explorer

I have the same question! I cannot find a way to get rid of them...

0 Karma

bwooden
Splunk Employee
Splunk Employee

There are several options. The best approach depends on what you are ultimately trying to accomplish by removing them. Please add more detail.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...