<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to delete specific event? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-specific-event/m-p/59467#M11721</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;How can I delete some specific event in Splunk? For example, one log loaded in splunk with 50 events, and I want to delete one or two events in them.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Dec 2012 11:52:43 GMT</pubDate>
    <dc:creator>ford1863</dc:creator>
    <dc:date>2012-12-11T11:52:43Z</dc:date>
    <item>
      <title>How to delete specific event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-specific-event/m-p/59467#M11721</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;How can I delete some specific event in Splunk? For example, one log loaded in splunk with 50 events, and I want to delete one or two events in them.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2012 11:52:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-specific-event/m-p/59467#M11721</guid>
      <dc:creator>ford1863</dc:creator>
      <dc:date>2012-12-11T11:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to delete specific event?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-specific-event/m-p/59468#M11722</link>
      <description>&lt;P&gt;Use the &lt;CODE&gt;delete&lt;/CODE&gt; operator.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Delete"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Delete&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Note that you need the &lt;CODE&gt;can_delete&lt;/CODE&gt; privileged in order to be able to use this, and by default no roles (not even admin) have this privilege, so you'll need to add it before you can use this command.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2012 11:58:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-delete-specific-event/m-p/59468#M11722</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-12-11T11:58:54Z</dc:date>
    </item>
  </channel>
</rss>

