Hi Splunk Team,
There is an option to clear entire indexed data using the command "./splunk clean eventdata", it will delete entire data which has been indexed if it has for 3 months.
But my requirements to delete the indexed data for 10 or 30 minutes, is there any option to delete the indexed data using duration.
Thanks in advance.
Warm Regards,
Dhanasekaran.M
Here is what you can do:
http://docs.splunk.com/Documentation/Splunk/5.0.2/Indexer/RemovedatafromSplunk
It is possible to delete entire "buckets" of data if you know what you are doing. Using the dbinspect
command, you can find the buckets that contain data from the time range of interest, then stop and remove the directories. However, this will almost certainly also remove information that is outside of the data you're looking for, unless you're quite lucky.
No. You can hide data selectively using the delete command, but this will not clear up disk space.