Splunk Enterprise

How do I remove Sources?

howardhon
Engager

Hi ALL~

How do I remove Sources from my 'Sources Indexed'?

Thx.

Tags (1)

Genti
Splunk Employee
Splunk Employee

unfortunately, | delete will not actually make the sources not show up. A bug makes it so the sources will still show up, but with a count of 0. (in the summary dashboard, that is)

Again, it all depends on what you are trying to do, just like Bwooden said...

0 Karma

TheGU
Path Finder

Put the [| delete] after your specific source [source="zzzzzz" | delete]

But you need to add can_delete role to your account before do above process

0 Karma

rupesh_patil20
Path Finder

Hi .. where to use this command, i have tried in search but it didnt work out

0 Karma

fribert
Explorer

shahamit
Explorer

I am using splunk 5.0.2 and the above link does not apply for the latest version. How can I delete a source or sourcetype from the splunk server? The reason I want to delete the source/sourcetype is to reorganize my search dashboard. Currently I have configured the splunk universal forwarder to monitor glassfish logs (server.log file). With this configuration I see all the server.log* files transferred to the splunk server. I want them to be grouped them into one logical group since I have multiple instances and clusters configured on glassfish. How do I do that?

0 Karma

howardhon
Engager

thx fribert ^___^

0 Karma

fribert
Explorer

I have the same question! I cannot find a way to get rid of them...

0 Karma

bwooden
Splunk Employee
Splunk Employee

There are several options. The best approach depends on what you are ultimately trying to accomplish by removing them. Please add more detail.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...