<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HOW TO: Purge (CLEAN) Selective Data from an Index in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/HOW-TO-Purge-CLEAN-Selective-Data-from-an-Index/m-p/434515#M6249</link>
    <description>&lt;P&gt;I'll give it a shot and see what happens.&lt;/P&gt;

&lt;P&gt;Regarding your considerations:&lt;BR /&gt;
1. I was under the impression that "collect" automatically sets the sourcetype to 'stash' - is that not true?&lt;BR /&gt;
2. Can you give an example of which &lt;EM&gt;search extractions might not work&lt;/EM&gt;; and what are you referring to exactly when you say "&lt;EM&gt;as you have a new sourcetypes&lt;/EM&gt;?" &lt;BR /&gt;
3. I assume that i would need to put the index in 'single-user' mode so as to prevent reads and then pause the data connectors to stop any writes.&lt;BR /&gt;
4. I don't have a clustered architecture; i have a small, dev implementation.&lt;/P&gt;

&lt;P&gt;Thanks for the reply.&lt;BR /&gt;
regards&lt;/P&gt;</description>
    <pubDate>Tue, 30 Apr 2019 15:39:00 GMT</pubDate>
    <dc:creator>salighie</dc:creator>
    <dc:date>2019-04-30T15:39:00Z</dc:date>
    <item>
      <title>HOW TO: Purge (CLEAN) Selective Data from an Index</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/HOW-TO-Purge-CLEAN-Selective-Data-from-an-Index/m-p/434513#M6247</link>
      <description>&lt;P&gt;According to the documentation i'm reading, permanently purging selective data (matching search filter/s) doesn't appear to be possible.&lt;/P&gt;

&lt;P&gt;I'm wondering if there isn't a work-around / procedure of sorts.&lt;/P&gt;

&lt;P&gt;For example, is it possible to swap the data, much like swapping partitions in a relational db:&lt;BR /&gt;
1. Extract / move the data i want to keep from "PROD" Index to a "TEMP" index (stash)&lt;BR /&gt;
    ex: index=PROD source=something other_filters | collect index=TEMP&lt;BR /&gt;
2. Clean the  "PROD" index&lt;BR /&gt;
    ex: splunk clean eventdata -index index_name&lt;BR /&gt;
3. re-inject the data from "TEMP" index back into "PROD"&lt;BR /&gt;
    ex: index=TEMP | collect index=PROD&lt;/P&gt;

&lt;P&gt;Thoughts/ guidance would be greatly appreciated.&lt;/P&gt;

&lt;P&gt;regards&lt;BR /&gt;
Seb&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/HOW-TO-Purge-CLEAN-Selective-Data-from-an-Index/m-p/434513#M6247</guid>
      <dc:creator>salighie</dc:creator>
      <dc:date>2020-09-30T00:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: HOW TO: Purge (CLEAN) Selective Data from an Index</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/HOW-TO-Purge-CLEAN-Selective-Data-from-an-Index/m-p/434514#M6248</link>
      <description>&lt;P&gt;imho your approach will work,&lt;BR /&gt;
however, consider couple of things:&lt;BR /&gt;
1. if youll use other sourcetype then &lt;CODE&gt;stash&lt;/CODE&gt; you will use data against license.&lt;BR /&gt;
2. some search extractions might not work as you have a new sourectypes&lt;BR /&gt;
3. if you have anything that calls your previous index, youll have to modify and modify again.&lt;BR /&gt;
4. will be very tough (to impossible) to use if you have an indexer cluster architecture&lt;/P&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 23:56:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/HOW-TO-Purge-CLEAN-Selective-Data-from-an-Index/m-p/434514#M6248</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-04-29T23:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: HOW TO: Purge (CLEAN) Selective Data from an Index</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/HOW-TO-Purge-CLEAN-Selective-Data-from-an-Index/m-p/434515#M6249</link>
      <description>&lt;P&gt;I'll give it a shot and see what happens.&lt;/P&gt;

&lt;P&gt;Regarding your considerations:&lt;BR /&gt;
1. I was under the impression that "collect" automatically sets the sourcetype to 'stash' - is that not true?&lt;BR /&gt;
2. Can you give an example of which &lt;EM&gt;search extractions might not work&lt;/EM&gt;; and what are you referring to exactly when you say "&lt;EM&gt;as you have a new sourcetypes&lt;/EM&gt;?" &lt;BR /&gt;
3. I assume that i would need to put the index in 'single-user' mode so as to prevent reads and then pause the data connectors to stop any writes.&lt;BR /&gt;
4. I don't have a clustered architecture; i have a small, dev implementation.&lt;/P&gt;

&lt;P&gt;Thanks for the reply.&lt;BR /&gt;
regards&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 15:39:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/HOW-TO-Purge-CLEAN-Selective-Data-from-an-Index/m-p/434515#M6249</guid>
      <dc:creator>salighie</dc:creator>
      <dc:date>2019-04-30T15:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: HOW TO: Purge (CLEAN) Selective Data from an Index</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/HOW-TO-Purge-CLEAN-Selective-Data-from-an-Index/m-p/434516#M6250</link>
      <description>&lt;P&gt;indeed &lt;CODE&gt;collect&lt;/CODE&gt; sets sourcetype to &lt;CODE&gt;stash&lt;/CODE&gt;&lt;BR /&gt;
most of the time, users apply search time extractions, as well as search filters to sourcetype. meaning that if you have a search &lt;CODE&gt;index=a sourcetype=b&lt;/CODE&gt; youll have to change it to &lt;CODE&gt;index=c sourcetype=stash&lt;/CODE&gt; &lt;BR /&gt;
also if you have field extractions based on sourcetype &lt;CODE&gt;b&lt;/CODE&gt; you will have to modify them&lt;BR /&gt;
not sure what &lt;CODE&gt;single-user&lt;/CODE&gt; mode means as describe, however, defiantly stop any incoming data as the &lt;CODE&gt;collect&lt;/CODE&gt; command will execute only on the data fetched at the search / execution time&lt;BR /&gt;
good luck with your purge!&lt;/P&gt;

&lt;P&gt;if it answers your questions, kindly accept the answers for others to know it worked for you&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 15:42:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/HOW-TO-Purge-CLEAN-Selective-Data-from-an-Index/m-p/434516#M6250</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-05-01T15:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: HOW TO: Purge (CLEAN) Selective Data from an Index</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/HOW-TO-Purge-CLEAN-Selective-Data-from-an-Index/m-p/434517#M6251</link>
      <description>&lt;P&gt;single-user mode as in prevent other accounts from searching the index while i'm running thru the procedure.&lt;/P&gt;

&lt;P&gt;Thanks, I'll run through the procedure and update on what i find.&lt;/P&gt;

&lt;P&gt;you have been very helpful and insightful. i wanted to award you some points but the system wont allow me - says i don't have enough Karma.&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 16:37:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/HOW-TO-Purge-CLEAN-Selective-Data-from-an-Index/m-p/434517#M6251</guid>
      <dc:creator>salighie</dc:creator>
      <dc:date>2019-05-01T16:37:25Z</dc:date>
    </item>
  </channel>
</rss>

