Splunk Search

Problem with sources in search

jaterlwj
Explorer

I know this may sound retarded, but I'm really new to Splunk so any help would be appreciated! I have been wondering. In the search app , how can I add/remove data from the "sources"?

I have removed all data inputs using the manager but the data is still there. I have tried adding new data inputs as well but to no avail.

The data source only references the first data that I fed it when I installed Splunk. Can any one be kind enough to help me?

Tags (2)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Mostly, you can't. Once the data is in, it's an administrative operation to remove it, and only with heavy restrictions.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk

View solution in original post

0 Karma

anujamk
Engager

I am facing the same problem! I can't find my newly added data input. It can't be accessed through Search! Why? Could anyone help me with this?

P.S. I am new to Splunk.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Mostly, you can't. Once the data is in, it's an administrative operation to remove it, and only with heavy restrictions.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk

0 Karma

jaterlwj
Explorer

Thank you for the suggestion! I would post it as a seperate question. 🙂

0 Karma

Ayn
Legend

That should be asked as a separate question with more details - generally if you just add a record to a source Splunk will not reindex everything (if it did, your license usage would grow exponentially), so there's something in your specific situation that makes it behave this way.

0 Karma

jaterlwj
Explorer

Ahh. I managed to clear the indexes using the CLI clean command! Thank you. 🙂

On a side note, I have tested and realized that when monitoring a file with let's say 24 rows with the option "Continuously index data from a file or directory this Splunk instance can access".

I noticed that when I add a new row and refreshes. There are now 49 rows. The older 24 records are being duplicated. Is there any option to stop duplicate rows?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...