Deployment Architecture

Flush all logs in indexes

pdash
Path Finder

I want to flush all the logs in my indexes in splunk server.
I am stopping the splunk process
And then doing splunk clean eventdata
But even though it shows all cleaned when i restart splunk I see hot_v1_9 folder still in the db.
How do I flush every log in the index?

Tags (1)
0 Karma

Drainy
Champion

Does the hot_v1_9 folder have a particularly large size? Splunk will create a new hot bucket as it starts for an active index and if there is any data for it.

Drainy
Champion

Take a backup first but if you stop Splunk and delete the folder so no buckets exist it should create them as needed.

0 Karma

pdash
Path Finder

yes its around 1.2G. So will it affect if i delete these folders? I dont need the indexed data anyways.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...