<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to delete indexed data from disk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/563000#M100311</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237377"&gt;@vtrend&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no other command except clean to wipe out data from disk however as you said it will do whole index not a particular source.&lt;/P&gt;&lt;P&gt;| delete&amp;nbsp; command is something you already did meaning you won't be able to search it again but data exist on disk. When you re-ingest data from same source that you have deleted newly ingested will be searchable without issues.&lt;/P&gt;&lt;P&gt;--&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
    <pubDate>Thu, 12 Aug 2021 00:11:01 GMT</pubDate>
    <dc:creator>venkatasri</dc:creator>
    <dc:date>2021-08-12T00:11:01Z</dc:date>
    <item>
      <title>How to delete indexed data from disk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/562996#M100310</link>
      <description>&lt;P&gt;I have an&lt;FONT face="andale mono,times"&gt; index = 'telemetry'&lt;/FONT&gt; which gets data from a local directory on standalone Splunk installation.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I deleted some data from above index which came in from particular directory using command&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="andale mono,times"&gt;index='telemetry'&amp;nbsp;&amp;nbsp;source="/data/01/*" | delete&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;The above index has still more data from other sources (e.g. "&lt;FONT face="andale mono,times"&gt;/data/02&lt;/FONT&gt;" ..)&lt;BR /&gt;&lt;BR /&gt;I want to re-index the data from deleted directory i.e. "&lt;FONT face="andale mono,times"&gt;/data/01"&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;again.&lt;BR /&gt;Running &lt;STRONG&gt;&lt;FONT face="andale mono,times"&gt;splunk clean eventdata&lt;/FONT&gt;&lt;/STRONG&gt; involves&amp;nbsp;deleting entire index.&lt;BR /&gt;&lt;BR /&gt;I want to wipe from disk only that part of data that has been deleted above so that I can re-index it back. How can I achieve&amp;nbsp;this?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 23:33:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/562996#M100310</guid>
      <dc:creator>vtrend</dc:creator>
      <dc:date>2021-08-11T23:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to delete indexed data from disk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/563000#M100311</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237377"&gt;@vtrend&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no other command except clean to wipe out data from disk however as you said it will do whole index not a particular source.&lt;/P&gt;&lt;P&gt;| delete&amp;nbsp; command is something you already did meaning you won't be able to search it again but data exist on disk. When you re-ingest data from same source that you have deleted newly ingested will be searchable without issues.&lt;/P&gt;&lt;P&gt;--&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 00:11:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/563000#M100311</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-08-12T00:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to delete indexed data from disk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/563004#M100313</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp; Thanks Venkat for helping me out.&lt;BR /&gt;&lt;BR /&gt;I tested by re-ingesting same data but Splunk is not indexing it back, the job runs, but no results. Searching around the forums, few users mentioned I need to either clean the index or delete fishbuckets etc which I was trying to avoid.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 00:39:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/563004#M100313</guid>
      <dc:creator>vtrend</dc:creator>
      <dc:date>2021-08-12T00:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to delete indexed data from disk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/563005#M100314</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237377"&gt;@vtrend&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How are you re-ingesting the data from same source?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 00:42:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/563005#M100314</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-08-12T00:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to delete indexed data from disk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/563006#M100315</link>
      <description>&lt;P&gt;Yes, I have added local data directory with the path "&lt;FONT face="andale mono,times"&gt;/data/01/&lt;/FONT&gt;" and "Indexed Once' again.&lt;BR /&gt;I chose same Index and App Context while re-ingesting.&lt;BR /&gt;&lt;BR /&gt;However when I submit and complete above steps, the search query gives 0 results.&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;index='telemetry' source='/data/01/*'&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 00:46:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/563006#M100315</guid>
      <dc:creator>vtrend</dc:creator>
      <dc:date>2021-08-12T00:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to delete indexed data from disk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/563007#M100316</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237377"&gt;@vtrend&lt;/a&gt;&amp;nbsp;If you are using the same forwarder to re-index fishbucket ignores re-reading the same file contents.&lt;/P&gt;&lt;P&gt;Try clearing the fishbucket to specific source, replace - "/var/log/messages" with your source path&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;./splunk cmd btprobe -d  /opt/splunkforwarder/var/lib/splunk/fishbucket/splunk_private_db  --file /var/log/messages --reset&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 00:49:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/563007#M100316</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-08-12T00:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to delete indexed data from disk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/563008#M100317</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Ohh, this explains it. I'll try this and update here with the results.&lt;BR /&gt;&lt;BR /&gt;Thanks a lot.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 00:54:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-indexed-data-from-disk/m-p/563008#M100317</guid>
      <dc:creator>vtrend</dc:creator>
      <dc:date>2021-08-12T00:54:58Z</dc:date>
    </item>
  </channel>
</rss>

