Hey there... I am wanting to remove indexes that I created for testing purposed while installing splunk. It seems like a surgical task from what I am reading. Is there no functional way to do this without compromising the system?
Hi Brent, it's pretty straightforward. See the answer here : http://answers.splunk.com/answers/313100/how-do-i-delete-an-index.html#comment-312514
A link to the general doc is here : http://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk#Remove_an_index_enti...
Hey thanks for the response. My splunk cluster is not fully live yet and I want to reconfigure where all the index go because it is a mess right now... Is it possible to basically start over in term of how we lay out our indexes? I would need to do this for all indexes including the internal ones.