Getting Data In

Deleted events still showing in search summary

hughroberts
Explorer

Hi all

I deleted a large number of events taken through a UniversalForwarder (v5.0.3) using the | delete command.

However these events are still showing up in the event counts on the Search summary page, they don't show up in a regular search only on the summary page.

Is there any way to fix these count totals?

Set up is clustered environment with 2 indexers, one cluster master and one search head, all servers are v5.0.3 running on Windows 2008.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

It can take some time (as much as an hour or so) for the metadata to be updated after a delete command.

hughroberts
Explorer

thanks for the tip, its been that way for 24 hours, think there is a bucket issue, am looking at doing a meta.dirty to force a rebuild of the metsdata.

ShaneNewman
Motivator

Is there a chance you have used search optimization? If you have, splunk creates a summary index, meaning the historical data will still be in that summary index.

0 Karma

hughroberts
Explorer

hmmmm, should not be on for that specific index but its a possible, thanks for the tip, its give me some things to investigate

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...