I have some searches that in the Settings -> Searches, reports and alerts
it doesn't have a delete link. I've tried googling and other searches to find a way to delete these searches without coming up with an answer, other than trying to use the REST API to delete them, but I don't want to go there unless I have to. Here is what I see:
Note that there are two searches that don't have a Delete link. I'm logged in as myself, the owner of the search, and as admin, but none of these has a Delete link. Is there some command line way to do this? We have a search head cluster, so I can't just go delete it from the file without causing other issues.
Any ideas how to delete these searches without jumping through the REST API hoops?
Thanks!
I've seen this issue before and I believe its a bug. You could aways delete the saved search directly from savedsearches.conf. Another thing to try is to toggle the app context dropdown (all apps) to see if it will give you access to delete button.
Thanks for the suggestions. We had this same sort of problem back on 4.3.2, but when we upgraded to 6.0 it fixed those problems. If this is a bug, it's still in there, or was reintroduced with on the the updates since. We are currently on 6.4.1.
Tried the global (all apps) permission, that that didn't do it.
The problem with removing it from savedsearches.conf is that we are in a search head cluster, and deleting it from one search head doesn't delete it from any other, and it can cause problems if you delete it from each search head manually (so I've seen anyway). Splunk docs say to remove something from the SHC that you have to do it through the UI, or command line (splunk cmd ...) in order to maintain consistency across the cluster.
If I can't get a good way, I'll TRY using the REST API.
Thanks again.