I want to flush all the logs in my indexes in splunk server.
I am stopping the splunk process
And then doing splunk clean eventdata
But even though it shows all cleaned when i restart splunk I see hot_v1_9 folder still in the db.
How do I flush every log in the index?
Does the hot_v1_9 folder have a particularly large size? Splunk will create a new hot bucket as it starts for an active index and if there is any data for it.
Take a backup first but if you stop Splunk and delete the folder so no buckets exist it should create them as needed.
yes its around 1.2G. So will it affect if i delete these folders? I dont need the indexed data anyways.