<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: need basic directions for cleaning out indexed data in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/need-basic-directions-for-cleaning-out-indexed-data/m-p/96420#M5272</link>
    <description>&lt;P&gt;1) when logged in, you can find the indexes, in Manager (top right) -&amp;gt; Indexes (middle left). You have probably all your events in the index called 'main', which is the default index. &lt;/P&gt;

&lt;P&gt;To run the &lt;CODE&gt;clean&lt;/CODE&gt; command, you do not need to know the directory or filenames of where the data is stored. Only the name of the index.&lt;/P&gt;

&lt;P&gt;2) &lt;CODE&gt;/opt/splunk/bin/splunk stop&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;3) see 2)&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
    <pubDate>Tue, 16 Apr 2013 19:22:33 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2013-04-16T19:22:33Z</dc:date>
    <item>
      <title>need basic directions for cleaning out indexed data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/need-basic-directions-for-cleaning-out-indexed-data/m-p/96419#M5271</link>
      <description>&lt;P&gt;I'm new to the tool and just attemtping to build a POC. I have limited disk space and have reached tis limit. tried command "./splunk clean eventdata -index &amp;lt;???&amp;gt;" but &lt;BR /&gt;
1) not positive as to how to determine what index files I should look for to finish the argument. Where do I identify each index?&lt;BR /&gt;
2) I get folloiwng message "In order to clean, Splunked must not be running" - How do I 'turn it off'?&lt;BR /&gt;
3) when running the above clean command, do I run this from the /bin or do I run from a different library?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2013 19:11:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/need-basic-directions-for-cleaning-out-indexed-data/m-p/96419#M5271</guid>
      <dc:creator>jchilovich</dc:creator>
      <dc:date>2013-04-16T19:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: need basic directions for cleaning out indexed data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/need-basic-directions-for-cleaning-out-indexed-data/m-p/96420#M5272</link>
      <description>&lt;P&gt;1) when logged in, you can find the indexes, in Manager (top right) -&amp;gt; Indexes (middle left). You have probably all your events in the index called 'main', which is the default index. &lt;/P&gt;

&lt;P&gt;To run the &lt;CODE&gt;clean&lt;/CODE&gt; command, you do not need to know the directory or filenames of where the data is stored. Only the name of the index.&lt;/P&gt;

&lt;P&gt;2) &lt;CODE&gt;/opt/splunk/bin/splunk stop&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;3) see 2)&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2013 19:22:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/need-basic-directions-for-cleaning-out-indexed-data/m-p/96420#M5272</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-04-16T19:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: need basic directions for cleaning out indexed data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/need-basic-directions-for-cleaning-out-indexed-data/m-p/96421#M5273</link>
      <description>&lt;P&gt;Thank you. This cleared out what I needed. Can I follow up with yet another question?&lt;/P&gt;

&lt;P&gt;What kind of script do I need (or whatever the process would be) to clean out all data after say 7 days? A weeks worth of data should be more than enough for any RCA needed.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 17:38:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/need-basic-directions-for-cleaning-out-indexed-data/m-p/96421#M5273</guid>
      <dc:creator>jchilovich</dc:creator>
      <dc:date>2013-04-18T17:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: need basic directions for cleaning out indexed data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/need-basic-directions-for-cleaning-out-indexed-data/m-p/96422#M5274</link>
      <description>&lt;P&gt;You don't need a script.&lt;BR /&gt;
May I suggest reading up on how to configure your index(es) to define data retention?&lt;BR /&gt;
This may be helpful:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Indexer/HowSplunkstoresindexes"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/Indexer/HowSplunkstoresindexes&lt;/A&gt; &lt;BR /&gt;
&lt;A href="http://wiki.splunk.com/Deploy:BucketRotationAndRetention"&gt;http://wiki.splunk.com/Deploy:BucketRotationAndRetention&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 18:39:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/need-basic-directions-for-cleaning-out-indexed-data/m-p/96422#M5274</guid>
      <dc:creator>stefandagerman</dc:creator>
      <dc:date>2013-04-18T18:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: need basic directions for cleaning out indexed data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/need-basic-directions-for-cleaning-out-indexed-data/m-p/96423#M5275</link>
      <description>&lt;P&gt;Well, the easiest would be to set the limit on the amount of data, if you are not yet up to speed on config files. &lt;/P&gt;

&lt;P&gt;Go into Manager -&amp;gt; Indexes and select the index you're putting data into (&lt;CODE&gt;main&lt;/CODE&gt; most likely). There you can set the total amount of data the index can hold (in MB).&lt;/P&gt;

&lt;P&gt;If you want to set the retention on age, you'll have to create/edit a config file called &lt;CODE&gt;indexes.conf&lt;/CODE&gt; in /opt/splunk/etc/system/local, roughly like this;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[main]&lt;BR /&gt;
frozenTimePeriodInSecs = xxx&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Be aware though that messing with this file and getting it wrong, can result in an unusable system or loss of data.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 18:47:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/need-basic-directions-for-cleaning-out-indexed-data/m-p/96423#M5275</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-04-18T18:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: need basic directions for cleaning out indexed data</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/need-basic-directions-for-cleaning-out-indexed-data/m-p/96424#M5276</link>
      <description>&lt;P&gt;where &lt;CODE&gt;xxx&lt;/CODE&gt; would be seconds; 60 * 60 * 24 * 7 = 604800&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 18:49:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/need-basic-directions-for-cleaning-out-indexed-data/m-p/96424#M5276</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-04-18T18:49:01Z</dc:date>
    </item>
  </channel>
</rss>

