<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Delete logs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Delete-logs/m-p/555346#M157642</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;You have to create a search that returns only the results that should be deleted (correct search terms and correct time range). After that, you should add the "delete" command.&lt;BR /&gt;Example:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt; | delete&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;The data is not removed from the index, but it will not be returned on future searches. To use the command you need to run the search with an user with a role with capability "delete_by_keyword"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jun 2021 16:45:16 GMT</pubDate>
    <dc:creator>danielcj</dc:creator>
    <dc:date>2021-06-10T16:45:16Z</dc:date>
    <item>
      <title>Delete logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Delete-logs/m-p/555344#M157641</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;How can I delete my logs permanently&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Request to delete old Splunk logs for EMS and Truvue webservices that are older than 05/17/2021.&lt;BR /&gt;* Long Description&lt;BR /&gt;Request to delete old Splunk logs for EMS (App id: 2926) and Truvue webservices (App id: 637) that are older than 05/17/2021 as required by Experian GSO as these&lt;BR /&gt;logs contained plain text Pll data.&lt;BR /&gt;As part of an Insider Threat audit currently being performed the following Splunk index was flagged as containing clear text Pll data originating from a production&lt;BR /&gt;host.&lt;BR /&gt;eits_ec_prod_us&lt;BR /&gt;Items in Index: Name/Address/DOB/SSN&lt;BR /&gt;Host names:&lt;BR /&gt;mckecpap043v&lt;BR /&gt;mckecpap044&lt;BR /&gt;I&lt;BR /&gt;alnecsap456V&lt;BR /&gt;alnecsap455v&lt;BR /&gt;Source = /logs/TRUVUEWS_V6/TRUVUEWS_V6-std.log&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 16:38:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Delete-logs/m-p/555344#M157641</guid>
      <dc:creator>anil1432</dc:creator>
      <dc:date>2021-06-10T16:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Delete logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Delete-logs/m-p/555346#M157642</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;You have to create a search that returns only the results that should be deleted (correct search terms and correct time range). After that, you should add the "delete" command.&lt;BR /&gt;Example:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your_search&amp;gt; | delete&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;The data is not removed from the index, but it will not be returned on future searches. To use the command you need to run the search with an user with a role with capability "delete_by_keyword"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 16:45:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Delete-logs/m-p/555346#M157642</guid>
      <dc:creator>danielcj</dc:creator>
      <dc:date>2021-06-10T16:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Delete logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Delete-logs/m-p/555429#M157664</link>
      <description>&lt;P&gt;So I need to delete only events from my from my logs. i.e from 17/05/2021 to delete events . How can I ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 05:20:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Delete-logs/m-p/555429#M157664</guid>
      <dc:creator>anil1432</dc:creator>
      <dc:date>2021-06-11T05:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Delete logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Delete-logs/m-p/555461#M157671</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/44004"&gt;@anil1432&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;you can filter your logs in the search (i.e. index=xyz host=xyz) and set the time selection (i.e. Date Range - Between - 17/05/2021 00:00:00 and 17/05/2021 24:00:00) and then type the "| delete" command, then the filtered events will me deleted (marked as deleted). The Data / events are still on the Storage / in the Index.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 10:57:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Delete-logs/m-p/555461#M157671</guid>
      <dc:creator>eichfuss</dc:creator>
      <dc:date>2021-06-11T10:57:44Z</dc:date>
    </item>
  </channel>
</rss>

