Deployment Architecture

Flush all logs in indexes

pdash
Path Finder

I want to flush all the logs in my indexes in splunk server.
I am stopping the splunk process
And then doing splunk clean eventdata
But even though it shows all cleaned when i restart splunk I see hot_v1_9 folder still in the db.
How do I flush every log in the index?

Tags (1)
0 Karma

Drainy
Champion

Does the hot_v1_9 folder have a particularly large size? Splunk will create a new hot bucket as it starts for an active index and if there is any data for it.

Drainy
Champion

Take a backup first but if you stop Splunk and delete the folder so no buckets exist it should create them as needed.

0 Karma

pdash
Path Finder

yes its around 1.2G. So will it affect if i delete these folders? I dont need the indexed data anyways.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...