<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it safe to clear event data from _internal? in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Is-it-safe-to-clear-event-data-from-internal/m-p/12757#M6951</link>
    <description>&lt;P&gt;Is it safe to clear the _internal index like this?  Or should this never be done in the first place?  What are the issues that could arise from doing this?&lt;/P&gt;

&lt;P&gt;$SPLUNK_HOME/bin/splunk clean eventdata -index _internal&lt;/P&gt;</description>
    <pubDate>Mon, 03 May 2010 03:00:04 GMT</pubDate>
    <dc:creator>rayfoo</dc:creator>
    <dc:date>2010-05-03T03:00:04Z</dc:date>
    <item>
      <title>Is it safe to clear event data from _internal?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Is-it-safe-to-clear-event-data-from-internal/m-p/12757#M6951</link>
      <description>&lt;P&gt;Is it safe to clear the _internal index like this?  Or should this never be done in the first place?  What are the issues that could arise from doing this?&lt;/P&gt;

&lt;P&gt;$SPLUNK_HOME/bin/splunk clean eventdata -index _internal&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2010 03:00:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Is-it-safe-to-clear-event-data-from-internal/m-p/12757#M6951</guid>
      <dc:creator>rayfoo</dc:creator>
      <dc:date>2010-05-03T03:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Is it safe to clear event data from _internal?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Is-it-safe-to-clear-event-data-from-internal/m-p/12758#M6952</link>
      <description>&lt;P&gt;Yes, it's safe to do. Other than not having the internal logs anymore, it doesn't cause any harm.&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2010 05:38:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Is-it-safe-to-clear-event-data-from-internal/m-p/12758#M6952</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-05-03T05:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Is it safe to clear event data from _internal?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Is-it-safe-to-clear-event-data-from-internal/m-p/12759#M6953</link>
      <description>&lt;P&gt;I did this, so what do I need to do if I want it enabled again ? I see the directory for _internal growing but search just isn't seeing it anymore.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2012 19:31:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Is-it-safe-to-clear-event-data-from-internal/m-p/12759#M6953</guid>
      <dc:creator>rsia23</dc:creator>
      <dc:date>2012-01-24T19:31:12Z</dc:date>
    </item>
  </channel>
</rss>

