Splunk Search

"how to cancel the data source"

johnsmithcy
Path Finder

the host monitoring keep fetching the CPU data.
I want to cancel the date source

Tags (1)
0 Karma
1 Solution

dkeck
Influencer

Hi,

depending from where you are getting your data you just have to disable the stanza in inputs.conf on your forwarder to stop it from sending.

View solution in original post

0 Karma

MoniM
Communicator

Hi @johnsmithcy,

you can use the below command in CLI:-

sourcetype=my_sourcetype | delete
For more details check this http://www.splunk.com/base/Documentation/4.1.1/Admin/RemovedatafromSplunk

0 Karma

johnsmithcy
Path Finder

thank you. any graphical interface method?
I am using windows version

0 Karma

MoniM
Communicator

Okay, so you can delete your sourcetype by following below steps:-
1. login to your splunk instance and goto settings
2. In data, goto sourcetypes and search for your sorectype(which you created for your "CPU" input).
3. delete that sourcetype.

Let me know if it works.

0 Karma

johnsmithcy
Path Finder

it works, thx

0 Karma

dkeck
Influencer

Hi,

depending from where you are getting your data you just have to disable the stanza in inputs.conf on your forwarder to stop it from sending.

0 Karma

johnsmithcy
Path Finder

i configure it through "add data"--> "monitor" --> local performance monitoring

0 Karma

dkeck
Influencer

Then try to find it under settings-> data inputs -> local Windows or local perfomance monitoring 🙂 than click delete or disable

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...