Splunk Search

How to block or remove sourcetype in windows

armaanxman
Engager

I am testing Splunk on windows 2k8 R2. The sourcetype = "trc" (log file) is really huge in size and I want to block it or remove it. This sourcetype is uploading so much data. Please help.

Tags (5)
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

You can't really block a sourcetype in the sense of stopping traffic from coming in except by disabling the input which is responsible for handling this data. If you didn't want this data coming in any longer, you can blacklist it at the input level.

http://docs.splunk.com/Documentation/Splunk/latest/Data/Whitelistorblacklistspecificincomingdata

You can also route data you don't want indexed to nullQueue using the instructions here:

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad#Filter_event_data_and_...

You can't really remove data in a surgical fashion. You can | delete it, but that won't reclaim the space used by the events.

Your options for removing data are discussed here:

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

You can't really block a sourcetype in the sense of stopping traffic from coming in except by disabling the input which is responsible for handling this data. If you didn't want this data coming in any longer, you can blacklist it at the input level.

http://docs.splunk.com/Documentation/Splunk/latest/Data/Whitelistorblacklistspecificincomingdata

You can also route data you don't want indexed to nullQueue using the instructions here:

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad#Filter_event_data_and_...

You can't really remove data in a surgical fashion. You can | delete it, but that won't reclaim the space used by the events.

Your options for removing data are discussed here:

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...