Splunk Search

Problem with sources in search

jaterlwj
Explorer

I know this may sound retarded, but I'm really new to Splunk so any help would be appreciated! I have been wondering. In the search app , how can I add/remove data from the "sources"?

I have removed all data inputs using the manager but the data is still there. I have tried adding new data inputs as well but to no avail.

The data source only references the first data that I fed it when I installed Splunk. Can any one be kind enough to help me?

Tags (2)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Mostly, you can't. Once the data is in, it's an administrative operation to remove it, and only with heavy restrictions.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk

View solution in original post

0 Karma

anujamk
Engager

I am facing the same problem! I can't find my newly added data input. It can't be accessed through Search! Why? Could anyone help me with this?

P.S. I am new to Splunk.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Mostly, you can't. Once the data is in, it's an administrative operation to remove it, and only with heavy restrictions.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk

0 Karma

jaterlwj
Explorer

Thank you for the suggestion! I would post it as a seperate question. 🙂

0 Karma

Ayn
Legend

That should be asked as a separate question with more details - generally if you just add a record to a source Splunk will not reindex everything (if it did, your license usage would grow exponentially), so there's something in your specific situation that makes it behave this way.

0 Karma

jaterlwj
Explorer

Ahh. I managed to clear the indexes using the CLI clean command! Thank you. 🙂

On a side note, I have tested and realized that when monitoring a file with let's say 24 rows with the option "Continuously index data from a file or directory this Splunk instance can access".

I noticed that when I add a new row and refreshes. There are now 49 rows. The older 24 records are being duplicated. Is there any option to stop duplicate rows?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...