Hello,
I added a file csv in splunk but the name is not correct for sourcetype. And i want to restart.
now :
source="test.csv" sourcetype="csv"
I will want :
source="test.csv" sourcetype="test"
If i do this query, it's correct ?
source="test.csv" sourcetype="csv" | delete
it will delete test.csv file please ?
thanks in advance.
Regards,
Viat
Thanks for your reply.
I have this error message :
Error in 'delete' command: You have insufficient privileges to delete events.
How can I do please ?
Thanks in advance
Yes, you have to contact your splunk admin and get your user updated with more privileges / capabilities .
as your query is resolved, please accept @to4kawa 's answer as solution. thanks. karma points appreciated!
Please ask your administrator for help.
source="test.csv" sourcetype="csv" | delete
That's correct.