Deployment Architecture

Is it possible to delete an index from an indexer cluster without restarting the indexers?

lmcmipl
Explorer

I would like to delete all the data in an index from an indexer cluster without restarting the indexers.

Replication factor= 2 and search factor = 2.

Restarting the indexers causes the cluster master to reassign primaries to available searchable bucket copies. Since my system uses accelerated data models, which are not replicated, all the re-assigned primary buckets need to have their data model re-accelerated. In a large production system, this can take a considerable amount of time.

I am running Splunk V.6.2.3

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

So you cant delete the indexes, per say, without a restart.

However, there are a few things you could potentially do..

index=deleteme | delete

Delete all the events in the index (this doesnt actually delete, but marks them as deleted.) And this clean the index when time permits.

Maintenance Mode and Delete

Put your cluster into maintenance mode, this will prevent the bucket fixup activities across the cluster. While in maintenance mode, one by one, go through your indexers and clean / delete the index.

After you're done, take the cluster out of maintenance mode. You will still need to apply the cluster bundle to remove the index definition. But that will technically require another rolling restart. However, a rolling restart of the cluster will maintain your SF / RF and users should not notice downtime.

There is no way around the DM issue at this time. Splunk 6.4 should introduce the capability of replicated DM acceleration...

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...