I have a Windows server with the Universal Forwarder installed for testing.
I now want to remove that host and all data it has fed into Splunk, from Splunk.
I've uninstalled the forwarder, but I don't see how to remove it from Splunk itself - the old events are still there and it still shows on the "Data Summary" panel.
I tried `hostname | delete` from Splunk Web logged in as "admin" and it simply says I don't have rights which seems a bit odd logged in directly as "admin".
Thanks :)
↧