Splunk Enterprise

How do I remove Sources?

howardhon
Engager

Hi ALL~

How do I remove Sources from my 'Sources Indexed'?

Thx.

Tags (1)

Genti
Splunk Employee
Splunk Employee

unfortunately, | delete will not actually make the sources not show up. A bug makes it so the sources will still show up, but with a count of 0. (in the summary dashboard, that is)

Again, it all depends on what you are trying to do, just like Bwooden said...

0 Karma

TheGU
Path Finder

Put the [| delete] after your specific source [source="zzzzzz" | delete]

But you need to add can_delete role to your account before do above process

0 Karma

rupesh_patil20
Path Finder

Hi .. where to use this command, i have tried in search but it didnt work out

0 Karma

fribert
Explorer

shahamit
Explorer

I am using splunk 5.0.2 and the above link does not apply for the latest version. How can I delete a source or sourcetype from the splunk server? The reason I want to delete the source/sourcetype is to reorganize my search dashboard. Currently I have configured the splunk universal forwarder to monitor glassfish logs (server.log file). With this configuration I see all the server.log* files transferred to the splunk server. I want them to be grouped them into one logical group since I have multiple instances and clusters configured on glassfish. How do I do that?

0 Karma

howardhon
Engager

thx fribert ^___^

0 Karma

fribert
Explorer

I have the same question! I cannot find a way to get rid of them...

0 Karma

bwooden
Splunk Employee
Splunk Employee

There are several options. The best approach depends on what you are ultimately trying to accomplish by removing them. Please add more detail.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...