I am trying to figure out how to delete metrics data. "| delete" doesn't work with mstats, is there another way?
Thanks,
Vadim
You have to clear out the whole index (bin\splunk clean eventdata ...
), or, more unsafely, delete the buckets/directories from the file system containing the bad data.
As of now, there is no supporting of the delete
command. See my rantings here: https://answers.splunk.com/answers/579720/should-metrics-indexes-support-overwriting-events-1.html