Delete CrowdStrike data input

Delete a CrowdStrike data input from Data Manager when you no longer need to ingest data from that source.

When you delete a CrowdStrike data input, Data Manager removes the input configuration, deletes the associated Universal Cloud Forwarder (UCF) connector, and cleans up related configuration files.
  1. Log in to Splunk Cloud and select Data Manager.
  2. In the Ingest inputs tab, select the CrowdStrike data input that you want to delete.
  3. On the details section, select Delete.
  4. Confirm the deletion when prompted.

    The system initiates the deletion process, which includes the following results:

    • Removing the input from Data Manager.
    • Cleaning up related configuration.
    • Removing sensor event filters and CrowdStrike client configurations that are associated with this input, only if no other inputs reference them. Shared resources that are still in use by other inputs are preserved.
The CrowdStrike data input is removed from Data Manager and no longer appears in the Ingest inputs list. Data Manager stops ingesting data from the deleted source. Any data that was already ingested remains in your Splunk indexes and is not affected by the deletion.