Splunk Search

Problem with sources in search

jaterlwj
Explorer

I know this may sound retarded, but I'm really new to Splunk so any help would be appreciated! I have been wondering. In the search app , how can I add/remove data from the "sources"?

I have removed all data inputs using the manager but the data is still there. I have tried adding new data inputs as well but to no avail.

The data source only references the first data that I fed it when I installed Splunk. Can any one be kind enough to help me?

Tags (2)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Mostly, you can't. Once the data is in, it's an administrative operation to remove it, and only with heavy restrictions.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk

View solution in original post

0 Karma

anujamk
Engager

I am facing the same problem! I can't find my newly added data input. It can't be accessed through Search! Why? Could anyone help me with this?

P.S. I am new to Splunk.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Mostly, you can't. Once the data is in, it's an administrative operation to remove it, and only with heavy restrictions.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk

0 Karma

jaterlwj
Explorer

Thank you for the suggestion! I would post it as a seperate question. 🙂

0 Karma

Ayn
Legend

That should be asked as a separate question with more details - generally if you just add a record to a source Splunk will not reindex everything (if it did, your license usage would grow exponentially), so there's something in your specific situation that makes it behave this way.

0 Karma

jaterlwj
Explorer

Ahh. I managed to clear the indexes using the CLI clean command! Thank you. 🙂

On a side note, I have tested and realized that when monitoring a file with let's say 24 rows with the option "Continuously index data from a file or directory this Splunk instance can access".

I noticed that when I add a new row and refreshes. There are now 49 rows. The older 24 records are being duplicated. Is there any option to stop duplicate rows?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...