<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Delete specific data in cluster environment in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Delete-specific-data-in-cluster-environment/m-p/660228#M9838</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to delete only specific data from the specific index(note: not the entire data)in clustered environment&lt;/P&gt;</description>
    <pubDate>Tue, 10 Oct 2023 11:14:11 GMT</pubDate>
    <dc:creator>NOORULAINE</dc:creator>
    <dc:date>2023-10-10T11:14:11Z</dc:date>
    <item>
      <title>Delete specific data in cluster environment</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Delete-specific-data-in-cluster-environment/m-p/660228#M9838</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to delete only specific data from the specific index(note: not the entire data)in clustered environment&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 11:14:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Delete-specific-data-in-cluster-environment/m-p/660228#M9838</guid>
      <dc:creator>NOORULAINE</dc:creator>
      <dc:date>2023-10-10T11:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Delete specific data in cluster environment</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Delete-specific-data-in-cluster-environment/m-p/660230#M9839</link>
      <description>&lt;P&gt;With Splunk there is no way to delete data from the index other than the normal rolling oldest buckets to frozen.&lt;/P&gt;&lt;P&gt;There is the "delete" command but it doesn't actually delete the data from the index files (since the index files are immutable after creation and may be - as mentioned above - only rolled as a whole) but it marks that data as not searchable.&lt;/P&gt;&lt;P&gt;That's one of the reasons why you should test your configurations - especially the input-related elements - in a dev/test environment before deploying it to production.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 11:43:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Delete-specific-data-in-cluster-environment/m-p/660230#M9839</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-10-10T11:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: Delete specific data in cluster environment</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Delete-specific-data-in-cluster-environment/m-p/660268#M9840</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/260010"&gt;@NOORULAINE&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;said, it's possible to delete events (not the entire index) but it's only a logic deletion, not physical only, enabling the can_delete role for the user and it's a very dangerous feature that usually is disabled also for administrators.&lt;/P&gt;&lt;P&gt;The only phisical detetions are the splunk clean eventdata command, but it deletes the entire index and when a bucket rolls from cold at the end of the retention time.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 17:29:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Delete-specific-data-in-cluster-environment/m-p/660268#M9840</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-10T17:29:57Z</dc:date>
    </item>
  </channel>
</rss>

