Deployment Architecture

Deleting distinct data from index

iKate
Builder

Hello,
Can someone explain why there is no inbuilt functionality of deleting just some indexed data - from particular source or for particular date etc? Are there still not enough requests for this feature?

I know that it's better to create different indexes, but it's weird to make separate index for each search.
Importing to csv, editing and then reindexing as I've read is correlated with high risks.
Just hiding results from searches by "delete" won't move the data.
Cleaning entire index isn't a decision when lots of searches have already been indexed in it.

So can you please answer why is it so? And is it going to be solved?

Thanks

Tags (2)
0 Karma

mjhennig
Engager

Maybe this answer could help: http://splunk-base.splunk.com/answers/62516/delete-the-data-after-indexing -- Although it's still weird somehow, because one needs to stop the Splunk daemon before the operation..

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...