<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index cleared after disabling input? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-cleared-after-disabling-input/m-p/45658#M8588</link>
    <description>&lt;P&gt;All information will still be in the index and searchable.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Feb 2011 22:16:08 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2011-02-16T22:16:08Z</dc:date>
    <item>
      <title>Index cleared after disabling input?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-cleared-after-disabling-input/m-p/45657#M8587</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;when I have configured an input for log files, ie from a certain directory, and I disable it any time, will my index get cleared of this information or is the information still in my index and searchable?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2011 20:51:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-cleared-after-disabling-input/m-p/45657#M8587</guid>
      <dc:creator>StefanB</dc:creator>
      <dc:date>2011-02-16T20:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: Index cleared after disabling input?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-cleared-after-disabling-input/m-p/45658#M8588</link>
      <description>&lt;P&gt;All information will still be in the index and searchable.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2011 22:16:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-cleared-after-disabling-input/m-p/45658#M8588</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-02-16T22:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Index cleared after disabling input?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-cleared-after-disabling-input/m-p/45659#M8589</link>
      <description>&lt;P&gt;is there any way to clear the index then? or should i better be using different indexes then for every app?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2011 22:30:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-cleared-after-disabling-input/m-p/45659#M8589</guid>
      <dc:creator>StefanB</dc:creator>
      <dc:date>2011-02-16T22:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: Index cleared after disabling input?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-cleared-after-disabling-input/m-p/45660#M8590</link>
      <description>&lt;P&gt;You can clean a whole index by issuing "splunk clean -index &lt;YOURINDEX&gt;" from the command line. If you want to remove only specific events you can use the "delete" operator. Note however that events affected by "delete" won't actually disappear from the index, rather they will only be hidden, so they will still take up disk space. Deleted events disappear when they're moved to the frozen bucket, though.&lt;/YOURINDEX&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2011 22:42:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-cleared-after-disabling-input/m-p/45660#M8590</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-02-16T22:42:48Z</dc:date>
    </item>
  </channel>
</rss>

