Deployment Architecture

Deleting distinct data from index

iKate
Builder

Hello,
Can someone explain why there is no inbuilt functionality of deleting just some indexed data - from particular source or for particular date etc? Are there still not enough requests for this feature?

I know that it's better to create different indexes, but it's weird to make separate index for each search.
Importing to csv, editing and then reindexing as I've read is correlated with high risks.
Just hiding results from searches by "delete" won't move the data.
Cleaning entire index isn't a decision when lots of searches have already been indexed in it.

So can you please answer why is it so? And is it going to be solved?

Thanks

Tags (2)
0 Karma

mjhennig
Engager

Maybe this answer could help: http://splunk-base.splunk.com/answers/62516/delete-the-data-after-indexing -- Although it's still weird somehow, because one needs to stop the Splunk daemon before the operation..

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...