Well now I feel like a total newb. 😕 After trying some other things, I had simply tried the command as listed in the 3.4.14-centric article listed above and, when it failed, I (in frustration) moved on to more searching and asking here. Just now, I tried replacing the single-quotes with double-quotes...
C:\Program Files\Splunk\bin>splunk search " | oldsearch delete::sourcetype::WinRegistry"
... and it appears to be working fine. Thanks for the encouragement to look at it again, anyway. 🙂
... View more