Splunk Enterprise

How do I remove Sources?

howardhon
Engager

Hi ALL~

How do I remove Sources from my 'Sources Indexed'?

Thx.

Tags (1)

Genti
Splunk Employee
Splunk Employee

unfortunately, | delete will not actually make the sources not show up. A bug makes it so the sources will still show up, but with a count of 0. (in the summary dashboard, that is)

Again, it all depends on what you are trying to do, just like Bwooden said...

0 Karma

TheGU
Path Finder

Put the [| delete] after your specific source [source="zzzzzz" | delete]

But you need to add can_delete role to your account before do above process

0 Karma

rupesh_patil20
Path Finder

Hi .. where to use this command, i have tried in search but it didnt work out

0 Karma

fribert
Explorer

shahamit
Explorer

I am using splunk 5.0.2 and the above link does not apply for the latest version. How can I delete a source or sourcetype from the splunk server? The reason I want to delete the source/sourcetype is to reorganize my search dashboard. Currently I have configured the splunk universal forwarder to monitor glassfish logs (server.log file). With this configuration I see all the server.log* files transferred to the splunk server. I want them to be grouped them into one logical group since I have multiple instances and clusters configured on glassfish. How do I do that?

0 Karma

howardhon
Engager

thx fribert ^___^

0 Karma

fribert
Explorer

I have the same question! I cannot find a way to get rid of them...

0 Karma

bwooden
Splunk Employee
Splunk Employee

There are several options. The best approach depends on what you are ultimately trying to accomplish by removing them. Please add more detail.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...