Splunk Search

"how to cancel the data source"

johnsmithcy
Path Finder

the host monitoring keep fetching the CPU data.
I want to cancel the date source

Tags (1)
0 Karma
1 Solution

dkeck
Influencer

Hi,

depending from where you are getting your data you just have to disable the stanza in inputs.conf on your forwarder to stop it from sending.

View solution in original post

0 Karma

MoniM
Communicator

Hi @johnsmithcy,

you can use the below command in CLI:-

sourcetype=my_sourcetype | delete
For more details check this http://www.splunk.com/base/Documentation/4.1.1/Admin/RemovedatafromSplunk

0 Karma

johnsmithcy
Path Finder

thank you. any graphical interface method?
I am using windows version

0 Karma

MoniM
Communicator

Okay, so you can delete your sourcetype by following below steps:-
1. login to your splunk instance and goto settings
2. In data, goto sourcetypes and search for your sorectype(which you created for your "CPU" input).
3. delete that sourcetype.

Let me know if it works.

0 Karma

johnsmithcy
Path Finder

it works, thx

0 Karma

dkeck
Influencer

Hi,

depending from where you are getting your data you just have to disable the stanza in inputs.conf on your forwarder to stop it from sending.

0 Karma

johnsmithcy
Path Finder

i configure it through "add data"--> "monitor" --> local performance monitoring

0 Karma

dkeck
Influencer

Then try to find it under settings-> data inputs -> local Windows or local perfomance monitoring 🙂 than click delete or disable

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...