Splunk Search

How to block or remove sourcetype in windows

armaanxman
Engager

I am testing Splunk on windows 2k8 R2. The sourcetype = "trc" (log file) is really huge in size and I want to block it or remove it. This sourcetype is uploading so much data. Please help.

Tags (5)
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

You can't really block a sourcetype in the sense of stopping traffic from coming in except by disabling the input which is responsible for handling this data. If you didn't want this data coming in any longer, you can blacklist it at the input level.

http://docs.splunk.com/Documentation/Splunk/latest/Data/Whitelistorblacklistspecificincomingdata

You can also route data you don't want indexed to nullQueue using the instructions here:

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad#Filter_event_data_and_...

You can't really remove data in a surgical fashion. You can | delete it, but that won't reclaim the space used by the events.

Your options for removing data are discussed here:

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

You can't really block a sourcetype in the sense of stopping traffic from coming in except by disabling the input which is responsible for handling this data. If you didn't want this data coming in any longer, you can blacklist it at the input level.

http://docs.splunk.com/Documentation/Splunk/latest/Data/Whitelistorblacklistspecificincomingdata

You can also route data you don't want indexed to nullQueue using the instructions here:

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad#Filter_event_data_and_...

You can't really remove data in a surgical fashion. You can | delete it, but that won't reclaim the space used by the events.

Your options for removing data are discussed here:

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...