<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File cleanup on monitored directory question in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/File-cleanup-on-monitored-directory-question/m-p/52981#M7017</link>
    <description>&lt;OL&gt;
&lt;LI&gt; Yes, once data has been indexed by Splunk, you do not need the original files.&lt;/LI&gt;
&lt;LI&gt; By looking at the main dashboard, the "sources" list will show you all of the files that Splunk has indexed. Inspect the 'latest time' column to determine where Splunk is in its indexing. (Files under a gigabyte generally only take at most a few minutes to index; it completely depends on your hardware).&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Wed, 03 Aug 2011 19:11:57 GMT</pubDate>
    <dc:creator>Johnvey</dc:creator>
    <dc:date>2011-08-03T19:11:57Z</dc:date>
    <item>
      <title>File cleanup on monitored directory question</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/File-cleanup-on-monitored-directory-question/m-p/52980#M7016</link>
      <description>&lt;P&gt;I ran out of space as I am using the free version on an old server for some basic log monitoring.  I deleted some old stuff, but can't find an answer after looking here and on the old forum.&lt;/P&gt;

&lt;P&gt;If I am monitoring a directory (/var/xlogs).  Now xlogs is a basic folder that 2 webservers copy files hourly over to.  Those are now months old.  If I delete files from yesterday back, and they have been indexed, I assume the data is still there, right?&lt;/P&gt;

&lt;P&gt;Also, I am looking at the earliest and latest date.  The latest shows 7/25/11 as it ran out of space, so that's fixed and there are new files there.  How do I see what's not indexed yet as well as what is (hoping I can delete the files that are indexed).&lt;/P&gt;

&lt;P&gt;Tnx&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2011 18:16:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/File-cleanup-on-monitored-directory-question/m-p/52980#M7016</guid>
      <dc:creator>xlancealotx</dc:creator>
      <dc:date>2011-08-03T18:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: File cleanup on monitored directory question</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/File-cleanup-on-monitored-directory-question/m-p/52981#M7017</link>
      <description>&lt;OL&gt;
&lt;LI&gt; Yes, once data has been indexed by Splunk, you do not need the original files.&lt;/LI&gt;
&lt;LI&gt; By looking at the main dashboard, the "sources" list will show you all of the files that Splunk has indexed. Inspect the 'latest time' column to determine where Splunk is in its indexing. (Files under a gigabyte generally only take at most a few minutes to index; it completely depends on your hardware).&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 03 Aug 2011 19:11:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/File-cleanup-on-monitored-directory-question/m-p/52981#M7017</guid>
      <dc:creator>Johnvey</dc:creator>
      <dc:date>2011-08-03T19:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: File cleanup on monitored directory question</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/File-cleanup-on-monitored-directory-question/m-p/52982#M7018</link>
      <description>&lt;P&gt;Cool, thought so just wanted to confirm.  Thanks for both.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2011 14:47:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/File-cleanup-on-monitored-directory-question/m-p/52982#M7018</guid>
      <dc:creator>xlancealotx</dc:creator>
      <dc:date>2011-08-04T14:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: File cleanup on monitored directory question</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/File-cleanup-on-monitored-directory-question/m-p/52983#M7019</link>
      <description>&lt;P&gt;Just to make sure I understand this correctly, if I delete a file specified as a data input that has already been completely indexed, it is okay?&lt;/P&gt;

&lt;P&gt;I have some rather large files of old apache logs that have been indexed. I need to delete them to free up some space on the Splunk server. Just want to make sure that I won't lose the indexed/searchable data associated with these files.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2011 21:31:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/File-cleanup-on-monitored-directory-question/m-p/52983#M7019</guid>
      <dc:creator>atiu</dc:creator>
      <dc:date>2011-09-19T21:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: File cleanup on monitored directory question</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/File-cleanup-on-monitored-directory-question/m-p/52984#M7020</link>
      <description>&lt;P&gt;How to automatize the deletion of files using the Splunk Forwarder ?&lt;/P&gt;

&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2013 14:29:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/File-cleanup-on-monitored-directory-question/m-p/52984#M7020</guid>
      <dc:creator>dcampill</dc:creator>
      <dc:date>2013-03-25T14:29:35Z</dc:date>
    </item>
  </channel>
</rss>

