I've run into an issue with one of my indexes (web)! The partition is 300GB and is now full, how can I purge the index to reduce the size by maintaining a consistent DB table for search strings and for the Web proxies app reporting? Thanks
What do you mean by "purge" it?
If you want to free up space while keeping some data so searches still run, you could always reduce the size of the index, in indexes.conf, with "maxTotalDataSizeMB", then restart splunk to delete the oldest data.