<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Removing data from splunk by Host in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Removing-data-from-splunk-by-Host/m-p/84206#M17489</link>
    <description>&lt;P&gt;I put the universal forwarder on my computer to test splunk. Now that we have it up and running, I want to remove all data that came from my computer. Is there a way to remove data from splunk, based on host? I don't want to just hide the data by using "| delete" I want to completely remove the data.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jan 2013 19:25:16 GMT</pubDate>
    <dc:creator>jared_anderson</dc:creator>
    <dc:date>2013-01-10T19:25:16Z</dc:date>
    <item>
      <title>Removing data from splunk by Host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Removing-data-from-splunk-by-Host/m-p/84206#M17489</link>
      <description>&lt;P&gt;I put the universal forwarder on my computer to test splunk. Now that we have it up and running, I want to remove all data that came from my computer. Is there a way to remove data from splunk, based on host? I don't want to just hide the data by using "| delete" I want to completely remove the data.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2013 19:25:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Removing-data-from-splunk-by-Host/m-p/84206#M17489</guid>
      <dc:creator>jared_anderson</dc:creator>
      <dc:date>2013-01-10T19:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Removing data from splunk by Host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Removing-data-from-splunk-by-Host/m-p/84207#M17490</link>
      <description>&lt;P&gt;You can completely remove the data by cleaning an index as you see in the link below.  This is not something you can do by host however.  The delete command will allow you to remove data by host and make in unaccessible from the UI.  The indexed data still resides and takes up space on disk however until it is aged out.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk#Remove_data_from_one_or_all_indexes"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Indexer/RemovedatafromSplunk#Remove_data_from_one_or_all_indexes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2013 19:29:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Removing-data-from-splunk-by-Host/m-p/84207#M17490</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2013-01-10T19:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: Removing data from splunk by Host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Removing-data-from-splunk-by-Host/m-p/84208#M17491</link>
      <description>&lt;P&gt;Will this still affect the license?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2013 19:30:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Removing-data-from-splunk-by-Host/m-p/84208#M17491</guid>
      <dc:creator>jared_anderson</dc:creator>
      <dc:date>2013-01-10T19:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Removing data from splunk by Host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Removing-data-from-splunk-by-Host/m-p/84209#M17492</link>
      <description>&lt;P&gt;For the current day, data that you've already ingested, yes.  But you do get the ability to go over your daily license limit.  If it's splunk free you have 3 times in a 30 day period, if it's a purchased license you have 5 times in 30 days.  Data stored does not matter against the license other than the fact that you'll need a little more disk space to hold onto it depending on how much data you are talking about.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2013 19:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Removing-data-from-splunk-by-Host/m-p/84209#M17492</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2013-01-10T19:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Removing data from splunk by Host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Removing-data-from-splunk-by-Host/m-p/84210#M17493</link>
      <description>&lt;P&gt;Great. That is exactly what I needed to know. I went over two days in a row, and I was just cleaning up some stuff. I uninstalled the forwarder but just wanted to clean things up. Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2013 19:38:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Removing-data-from-splunk-by-Host/m-p/84210#M17493</guid>
      <dc:creator>jared_anderson</dc:creator>
      <dc:date>2013-01-10T19:38:03Z</dc:date>
    </item>
  </channel>
</rss>

