<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About delete command error. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316613#M59200</link>
    <description>&lt;P&gt;Ohk sure. So, the issue is that, when you ran first, you got error.. on second run, delete worked fine. Right?&lt;/P&gt;

&lt;P&gt;Is it a repeating issue? Try to rerun delete command for some sample logs (careful, data deleted is irreversible, ..once deleted, data can't be retrieved back)&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jan 2018 06:24:36 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2018-01-17T06:24:36Z</dc:date>
    <item>
      <title>About delete command error.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316610#M59197</link>
      <description>&lt;P&gt;In my environment SH, indexer 1, indexer 2 exist, and distributed search is done for indexers 1 and 2 from SH.&lt;/P&gt;

&lt;P&gt;Yesterday, since data was duplicated in indexers 1 and 2, I give can_delete role to admin user of SH, and executed delete command on SH.&lt;BR /&gt;
However, despite all the data of indexer 1 being displayed as "deleted", all the data of indexer 2 was "errors".&lt;BR /&gt;
Also, the following error message appeared.&lt;/P&gt;

&lt;P&gt;["hostname of indexer 2"] You do not have the capability to delete from "index name"&lt;/P&gt;

&lt;P&gt;However, when I executed the same command again, all the data of indexer 2 was "deleted" this time.&lt;/P&gt;

&lt;P&gt;I thought that connection of SH between indexer 2 was being disconnected when I executed delete command and received error messages,&lt;BR /&gt;
but there was no error that communication with the indexer 2 was interrupted.&lt;/P&gt;

&lt;P&gt;What is this phenomenon?&lt;BR /&gt;
It will be very helpful if someone tells me.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2018 10:55:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316610#M59197</guid>
      <dc:creator>yutaka1005</dc:creator>
      <dc:date>2018-01-16T10:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: About delete command error.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316611#M59198</link>
      <description>&lt;P&gt;hope the indexers are not clustered, right.&lt;/P&gt;

&lt;P&gt;One more thing....were you trying to delete data from real time search?&lt;/P&gt;

&lt;P&gt;Note: You cannot run the delete command during a real-time search; you cannot delete events as they come in. If you try to use delete during a real-time search, Splunk Enterprise will display an error.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 04:28:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316611#M59198</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2018-01-17T04:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: About delete command error.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316612#M59199</link>
      <description>&lt;P&gt;Thank you for comment!&lt;/P&gt;

&lt;P&gt;First, my indexers are not clustered.&lt;/P&gt;

&lt;P&gt;Second, I excuted delete with the specified search period not real-time search.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 06:17:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316612#M59199</guid>
      <dc:creator>yutaka1005</dc:creator>
      <dc:date>2018-01-17T06:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: About delete command error.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316613#M59200</link>
      <description>&lt;P&gt;Ohk sure. So, the issue is that, when you ran first, you got error.. on second run, delete worked fine. Right?&lt;/P&gt;

&lt;P&gt;Is it a repeating issue? Try to rerun delete command for some sample logs (careful, data deleted is irreversible, ..once deleted, data can't be retrieved back)&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 06:24:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316613#M59200</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2018-01-17T06:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: About delete command error.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316614#M59201</link>
      <description>&lt;P&gt;Did you see any errors in the splunkd or webservice log?&lt;/P&gt;

&lt;P&gt;Since re-running it worked correctly, I would be inclined to think it a transient error - but any logs indicating network connectivity issues would give some comfort that the issue was further down the stack than Splunk.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 08:39:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316614#M59201</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-17T08:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: About delete command error.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316615#M59202</link>
      <description>&lt;P&gt;Yes, you right.&lt;/P&gt;

&lt;P&gt;No it is first time.&lt;BR /&gt;
I want to retry, but I can not easily take sample logs and delete it...&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 06:03:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316615#M59202</guid>
      <dc:creator>yutaka1005</dc:creator>
      <dc:date>2018-01-18T06:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: About delete command error.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316616#M59203</link>
      <description>&lt;P&gt;No, I looked for it but I could not find it.&lt;/P&gt;

&lt;P&gt;I thought it is transient error too, but I can not find anything that can prove it ...&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 06:05:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316616#M59203</guid>
      <dc:creator>yutaka1005</dc:creator>
      <dc:date>2018-01-18T06:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: About delete command error.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316617#M59204</link>
      <description>&lt;P&gt;The reason this most likely failed on the 2nd indexer is that your authorization change may have yet to propagate to that indexer. By the time you tried again, the change made its way to indexer 2's bundle.&lt;/P&gt;

&lt;P&gt;A bit off topic but may be related, how big is your search bundle and are you seeing messages for it taking longer than expected to replicate?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 23:50:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316617#M59204</guid>
      <dc:creator>davpx</dc:creator>
      <dc:date>2018-01-18T23:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: About delete command error.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316618#M59205</link>
      <description>&lt;P&gt;Thank you for answer!&lt;/P&gt;

&lt;P&gt;The first sentence implies that propagation of information that "can_delete" was given to the "admin" user was delayed?&lt;/P&gt;

&lt;P&gt;Excuse me&lt;BR /&gt;
What does the second sentence mean?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 00:45:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316618#M59205</guid>
      <dc:creator>yutaka1005</dc:creator>
      <dc:date>2018-01-19T00:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: About delete command error.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316619#M59206</link>
      <description>&lt;P&gt;A search bundle is basically a copy of your search head configurations which are replicated to your indexer. If you have a lot of apps or some that contain large files, it can sometimes take awhile to replicate.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 01:23:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316619#M59206</guid>
      <dc:creator>davpx</dc:creator>
      <dc:date>2018-01-19T01:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: About delete command error.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316620#M59207</link>
      <description>&lt;P&gt;I got it.&lt;/P&gt;

&lt;P&gt;In my environment, there are not such many apps.&lt;BR /&gt;
So I do not think there will be a long time to replicate.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 04:00:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/About-delete-command-error/m-p/316620#M59207</guid>
      <dc:creator>yutaka1005</dc:creator>
      <dc:date>2018-01-19T04:00:42Z</dc:date>
    </item>
  </channel>
</rss>

