<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remove the index distributed setup in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Remove-the-index-distributed-setup/m-p/745491#M118494</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276234"&gt;@ws&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The&amp;nbsp;clean&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;&amp;nbsp;command does not work on clustered indexes&lt;/STRONG&gt; - See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk#How_to_delete:~:text=Note%3A-,The,-clean%20command%20does" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk#How_to_delete:~:text=Note%3A-,The,-clean%20command%20does&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;As the others have said, you could reduce the retention to basically nothing so that the data ages out, before then removing the indexes.conf stanza for the index and deploying out to your indexers. However note that this will not remove the old directory structure on the indexers for this index, if you want to completely remove it you will need to delete the folder structure on each node as per the docs &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk#How_to_delete:~:text=indexer%20cluster%20Once-,you%27ve,-applied%20the%20indexes" target="_self"&gt;"&lt;SPAN&gt;Once you've applied the&amp;nbsp;&lt;/SPAN&gt;indexes.conf&lt;SPAN&gt;&amp;nbsp;changes and the peer nodes have restarted, remove the index's directories from each peer node."&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Mon, 05 May 2025 14:22:07 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-05-05T14:22:07Z</dc:date>
    <item>
      <title>Remove the index distributed setup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Remove-the-index-distributed-setup/m-p/745458#M118488</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;After setting up a test index and ingesting a test record, I’m now planning to remove the index from the distributed setup.&lt;/P&gt;&lt;P&gt;Could anyone confirm the correct procedure for removing an index in a distributed environment with 3 indexers and a management node?&lt;/P&gt;&lt;P&gt;I normally run the following command at an all in one setup.&lt;/P&gt;&lt;P&gt;/opt/splunk/bin/splunk clean eventdata -index index_name&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2025 04:01:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Remove-the-index-distributed-setup/m-p/745458#M118488</guid>
      <dc:creator>ws</dc:creator>
      <dc:date>2025-05-05T04:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Remove the index distributed setup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Remove-the-index-distributed-setup/m-p/745460#M118489</link>
      <description>&lt;P&gt;What exactly do you want to do?&lt;/P&gt;&lt;P&gt;The command you provided will "empty" the index without touching its definition. Also, I haven't tried this in a cluster (I assume that's what you mean by 3 indexers and "a management node") but I'd expect the cluster to start fixups as soon as you do the operation on the first node unless you enable maintenance mode.&lt;/P&gt;&lt;P&gt;Anyway, if you want to leave the index definition but only remove the indexed events, that's one of the possibilities. Another one is to set very short retention period and let Splunk roll the buckets normally.&lt;/P&gt;&lt;P&gt;If you want to remove the index along with its definition, you have to remove it from indexes.conf on the CM, push the config bundle (this&amp;nbsp;&lt;EM&gt;will&lt;/EM&gt; trigger rolling restart of indexers) and then manually remove index directories from each indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2025 06:35:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Remove-the-index-distributed-setup/m-p/745460#M118489</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-05-05T06:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: Remove the index distributed setup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Remove-the-index-distributed-setup/m-p/745461#M118490</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276234"&gt;@ws&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the best approach is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;remove every input that sends logs to this index,&lt;/LI&gt;&lt;LI&gt;in Cluster Manager, put the retention (&lt;SPAN&gt;frozenTimePeriodInSecs)&amp;nbsp;&lt;/SPAN&gt;of this index to zero and push the configuration to Indexers,&lt;/LI&gt;&lt;LI&gt;after some minute, check that there isn't any log in the index, then remove the index from the Cluster Manager and push again the configuration.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2025 06:48:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Remove-the-index-distributed-setup/m-p/745461#M118490</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-05-05T06:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Remove the index distributed setup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Remove-the-index-distributed-setup/m-p/745491#M118494</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276234"&gt;@ws&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The&amp;nbsp;clean&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;&amp;nbsp;command does not work on clustered indexes&lt;/STRONG&gt; - See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk#How_to_delete:~:text=Note%3A-,The,-clean%20command%20does" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk#How_to_delete:~:text=Note%3A-,The,-clean%20command%20does&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;As the others have said, you could reduce the retention to basically nothing so that the data ages out, before then removing the indexes.conf stanza for the index and deploying out to your indexers. However note that this will not remove the old directory structure on the indexers for this index, if you want to completely remove it you will need to delete the folder structure on each node as per the docs &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk#How_to_delete:~:text=indexer%20cluster%20Once-,you%27ve,-applied%20the%20indexes" target="_self"&gt;"&lt;SPAN&gt;Once you've applied the&amp;nbsp;&lt;/SPAN&gt;indexes.conf&lt;SPAN&gt;&amp;nbsp;changes and the peer nodes have restarted, remove the index's directories from each peer node."&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2025 14:22:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Remove-the-index-distributed-setup/m-p/745491#M118494</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-05T14:22:07Z</dc:date>
    </item>
  </channel>
</rss>

