Splunk Search

"how to cancel the data source"

johnsmithcy
Path Finder

the host monitoring keep fetching the CPU data.
I want to cancel the date source

Tags (1)
0 Karma
1 Solution

dkeck
Influencer

Hi,

depending from where you are getting your data you just have to disable the stanza in inputs.conf on your forwarder to stop it from sending.

View solution in original post

0 Karma

MoniM
Communicator

Hi @johnsmithcy,

you can use the below command in CLI:-

sourcetype=my_sourcetype | delete
For more details check this http://www.splunk.com/base/Documentation/4.1.1/Admin/RemovedatafromSplunk

0 Karma

johnsmithcy
Path Finder

thank you. any graphical interface method?
I am using windows version

0 Karma

MoniM
Communicator

Okay, so you can delete your sourcetype by following below steps:-
1. login to your splunk instance and goto settings
2. In data, goto sourcetypes and search for your sorectype(which you created for your "CPU" input).
3. delete that sourcetype.

Let me know if it works.

0 Karma

johnsmithcy
Path Finder

it works, thx

0 Karma

dkeck
Influencer

Hi,

depending from where you are getting your data you just have to disable the stanza in inputs.conf on your forwarder to stop it from sending.

0 Karma

johnsmithcy
Path Finder

i configure it through "add data"--> "monitor" --> local performance monitoring

0 Karma

dkeck
Influencer

Then try to find it under settings-> data inputs -> local Windows or local perfomance monitoring 🙂 than click delete or disable

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...