Splunk Search

Problem with sources in search

jaterlwj
Explorer

I know this may sound retarded, but I'm really new to Splunk so any help would be appreciated! I have been wondering. In the search app , how can I add/remove data from the "sources"?

I have removed all data inputs using the manager but the data is still there. I have tried adding new data inputs as well but to no avail.

The data source only references the first data that I fed it when I installed Splunk. Can any one be kind enough to help me?

Tags (2)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Mostly, you can't. Once the data is in, it's an administrative operation to remove it, and only with heavy restrictions.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk

View solution in original post

0 Karma

anujamk
Engager

I am facing the same problem! I can't find my newly added data input. It can't be accessed through Search! Why? Could anyone help me with this?

P.S. I am new to Splunk.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Mostly, you can't. Once the data is in, it's an administrative operation to remove it, and only with heavy restrictions.

http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk

0 Karma

jaterlwj
Explorer

Thank you for the suggestion! I would post it as a seperate question. 🙂

0 Karma

Ayn
Legend

That should be asked as a separate question with more details - generally if you just add a record to a source Splunk will not reindex everything (if it did, your license usage would grow exponentially), so there's something in your specific situation that makes it behave this way.

0 Karma

jaterlwj
Explorer

Ahh. I managed to clear the indexes using the CLI clean command! Thank you. 🙂

On a side note, I have tested and realized that when monitoring a file with let's say 24 rows with the option "Continuously index data from a file or directory this Splunk instance can access".

I noticed that when I add a new row and refreshes. There are now 49 rows. The older 24 records are being duplicated. Is there any option to stop duplicate rows?

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...