I know this may sound retarded, but I'm really new to Splunk so any help would be appreciated! I have been wondering. In the search app , how can I add/remove data from the "sources"?
I have removed all data inputs using the manager but the data is still there. I have tried adding new data inputs as well but to no avail.
The data source only references the first data that I fed it when I installed Splunk. Can any one be kind enough to help me?
Mostly, you can't. Once the data is in, it's an administrative operation to remove it, and only with heavy restrictions.
http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk
I am facing the same problem! I can't find my newly added data input. It can't be accessed through Search! Why? Could anyone help me with this?
P.S. I am new to Splunk.
Mostly, you can't. Once the data is in, it's an administrative operation to remove it, and only with heavy restrictions.
http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk
Thank you for the suggestion! I would post it as a seperate question. 🙂
That should be asked as a separate question with more details - generally if you just add a record to a source Splunk will not reindex everything (if it did, your license usage would grow exponentially), so there's something in your specific situation that makes it behave this way.
Ahh. I managed to clear the indexes using the CLI clean command! Thank you. 🙂
On a side note, I have tested and realized that when monitoring a file with let's say 24 rows with the option "Continuously index data from a file or directory this Splunk instance can access".
I noticed that when I add a new row and refreshes. There are now 49 rows. The older 24 records are being duplicated. Is there any option to stop duplicate rows?