Objective
You may delete a device or application from EventLog Analyzer due to any of the following reasons:
This article offers a detailed information on how and when to delete the device, what happens when you delete a device from EventLog Analyzer.
Prerequisites
Steps to follow
Understand how deleting a device works.
Once you delete a device in EventLog Analyzer user interface, all its associated configuration like Custom reports, parsing rules, detection rules, will be deleted from the database.
Raw logs (live logs that are data stored in elasticsearch) will be removed only based on the configured Retention Settings. When a device or application is deleted, archive entry that includes file names, location(s), timestamp will be removed from the database. This will not remove the actual archive files even based on archive retention. Those files can be manually removed from the file system.
We recommend deleting a device only when you no longer need the device or application to be audited for your compliance and security.
When you misconfigured a device, you can perform the following actions based on the below case.
Case 1: Device or application added as a different log format and logs are yet to collected or just collected.
If the log are just collected, if you are alright for the data loss, you can proceed with next step. or refer Case 2
If the logs are yet to be collected,

Case 2: Device or application added as a different log format and logs are collected for a while.Click here to contact Technical support with the following details to review the case and check on the feasibility: Screenshot of Archive files name of the respective log source.
Number of archive files available in the location.
Build number of EventLog Analyzer.
Current log format and Required Log format
To free up the license, you can consider to perform the following based on the cases.
Case 1: The device or application is not longer needed for auditing requirement or security analysis.
Navigate to Settings >> Log source configuration
Select the appropriate category and locate the device or application.
Select the entry and choose delete to remove the source and its respective configuration.

NOTE: Once you delete the source, all the configurations will be removed, however using the archive files, you can load the archives anytime to view the data. Archives can be removed manually from the archive location. You can also consider the Case 2.
Case 2: The device or application is needed for auditing or security analysis for a period of time, however, the current and future logs are no longer required.
You can Disable the device instead of deleting it. Disabling the device will free up the license and pause the log collection attempts from the application.
Navigate to Settings >> Log source configuration
Locate the category and the device/application.
Select the entry and choose Disable
NOTE: Disabling the device will free up the license and retain all the configurations. You can load the data from Raw live logs, archives etc.
NOTE: Decommissioned devices will be auto flagged with status as decommissioned and license will be released automatically.
4. If your intention of deleting a source is to free up storage, we recommend you to revisit the decision as the configurations will be lost during deletion. Alternatively, you can consider the following to reduce the disk space.
Configure Log Collection Filter to collect only required logs.
Setup multiple archive policies to split the archive policy to have different storage locations with different archive retention settings. Refer Archive - Help document for more details. Migrate existing data to different location. Refer Data migration for more details.
Tips
Consider disabling a device over deleting a device as you may need the configuration for upcoming.
Decommissioned devices will be auto flagged with status as decommissioned and license will be released automatically.
Disabling the device will free up the license and retain all the configurations. You can load the data from Raw live logs, archives etc.
If you have accidentally deleted a device and would like to add the device, you can perform the following action to re-associate the archive entries with the same device.
Locate the archive files of the respective device in archive location
Note down the Device name value in the file name. (It can be hostname or IP address or FQDN or DNS Name)
Add the device in EventLog Analyzer with same Device name that you have noted in the above step.
Navigate to Settings >> Admin Settings >> Archive >> More and select Add Archive Entries
Related topics and articles