Splunk Search

Problem with sources in search

jaterlwj
Explorer

I know this may sound retarded, but I'm really new to Splunk so any help would be appreciated! I have been wondering. In the search app , how can I add/remove data from the "sources"?

I have removed all data inputs using the manager but the data is still there. I have tried adding new data inputs as well but to no avail.

The data source only references the first data that I fed it when I installed Splunk. Can any one be kind enough to help me?

Tags (2)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Mostly, you can't. Once the data is in, it's an administrative operation to remove it, and only with heavy restrictions.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk

View solution in original post

0 Karma

anujamk
Engager

I am facing the same problem! I can't find my newly added data input. It can't be accessed through Search! Why? Could anyone help me with this?

P.S. I am new to Splunk.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Mostly, you can't. Once the data is in, it's an administrative operation to remove it, and only with heavy restrictions.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk

0 Karma

jaterlwj
Explorer

Thank you for the suggestion! I would post it as a seperate question. 🙂

0 Karma

Ayn
Legend

That should be asked as a separate question with more details - generally if you just add a record to a source Splunk will not reindex everything (if it did, your license usage would grow exponentially), so there's something in your specific situation that makes it behave this way.

0 Karma

jaterlwj
Explorer

Ahh. I managed to clear the indexes using the CLI clean command! Thank you. 🙂

On a side note, I have tested and realized that when monitoring a file with let's say 24 rows with the option "Continuously index data from a file or directory this Splunk instance can access".

I noticed that when I add a new row and refreshes. There are now 49 rows. The older 24 records are being duplicated. Is there any option to stop duplicate rows?

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...