Splunk Search

How do you remove matching terms from searches?

ryan_t_gavin
New Member

In Splunk 7.1.2, when searching, it will suggest terms that have been indexed in the past. I have deleted some data, but the data is still showing in "matching terms" when i start typing in the search bar.

How do I remove it from there as well?

Tags (1)
0 Karma
1 Solution

Vijeta
Influencer

Hi Ryan,

You can go in your Account Settings and under Search select the option as "None"

View solution in original post

0 Karma

Vijeta
Influencer

Hi Ryan,

You can go in your Account Settings and under Search select the option as "None"

0 Karma

ryan_t_gavin
New Member

Vijeta,

This does solve the problem in short-term. In my case, though, we accidentally ingested passwords in a file. We do not want this visible to anyone regardless of role, so we deleted it (| delete). We like the matching terms normally as it is convenient when searching something like "host=" to have the list of hosts, but right now if we type "password" it will show the deleted data's content. I'd like to type "password" but not show the deleted data's content; only new data.

Thanks!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting V2

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...