Getting Data In

How do you delete an index from a Splunk deployment with a non-clustered Indexer setup?

aknsun
Path Finder

Hi,

I would like to remove an index using the Splunk remove index command.

My environment has a non-clustered Indexer setup ( to be soon clustered), but with a Clustered SH deployment.

Can you let me know the Best Practice to delete an index for the above mentioned deployment?

Do I need to run the command on all Indexers?

Thanks,

AKN

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, you must remove the index from all indexers on which it is present.
It's not necessary, but is a good practice to also remove the index from your search heads. Do that by editing the indexes.conf file in the appropriate app on your SHC deployer, then deploy.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Yes, you must remove the index from all indexers on which it is present.
It's not necessary, but is a good practice to also remove the index from your search heads. Do that by editing the indexes.conf file in the appropriate app on your SHC deployer, then deploy.

---
If this reply helps you, Karma would be appreciated.

aknsun
Path Finder

@richgalloway . Thanks for the quick response.

0 Karma

aknsun
Path Finder

Hi,
@richgalloway
I still see reference to the deleted Index on the DMC under Settings-> Monitoring Console -> Indexing -> Indexes and Volumes-> "Indexes and Volumes: Deployment".
The Indexers have not been restarted after the Index removal. Neither has the DMC been restarted,

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...