Getting Data In

Can't delete a saved search - Do I have to try it with REST or is there another way?

cpetterborg
SplunkTrust
SplunkTrust

I have some searches that in the Settings -> Searches, reports and alerts it doesn't have a delete link. I've tried googling and other searches to find a way to delete these searches without coming up with an answer, other than trying to use the REST API to delete them, but I don't want to go there unless I have to. Here is what I see:

alt text

Note that there are two searches that don't have a Delete link. I'm logged in as myself, the owner of the search, and as admin, but none of these has a Delete link. Is there some command line way to do this? We have a search head cluster, so I can't just go delete it from the file without causing other issues.

Any ideas how to delete these searches without jumping through the REST API hoops?

Thanks!

  • - As additional information, the search cannot be reverted back to a private search from one that it available within the app.

the_wolverine
Champion

I've seen this issue before and I believe its a bug. You could aways delete the saved search directly from savedsearches.conf. Another thing to try is to toggle the app context dropdown (all apps) to see if it will give you access to delete button.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Thanks for the suggestions. We had this same sort of problem back on 4.3.2, but when we upgraded to 6.0 it fixed those problems. If this is a bug, it's still in there, or was reintroduced with on the the updates since. We are currently on 6.4.1.

Tried the global (all apps) permission, that that didn't do it.

The problem with removing it from savedsearches.conf is that we are in a search head cluster, and deleting it from one search head doesn't delete it from any other, and it can cause problems if you delete it from each search head manually (so I've seen anyway). Splunk docs say to remove something from the SHC that you have to do it through the UI, or command line (splunk cmd ...) in order to maintain consistency across the cluster.

If I can't get a good way, I'll TRY using the REST API.

Thanks again.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...