<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Messed up input data ruining/slowing down search? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Messed-up-input-data-ruining-slowing-down-search/m-p/99097#M25581</link>
    <description>&lt;P&gt;Hi! &lt;/P&gt;

&lt;P&gt;I accidentally indexed really bizarre logs (partially downloaded logs)  and assigned it to a sourcetype. Now searches in this sourcetype is extremely slow and I get inconsistent and bizarre results. I then deleted them from my input directory but it seems like they still exist. Is there anyway to clear or erase the history?&lt;/P&gt;

&lt;P&gt;I used the  | delete command and it looks like it's gone, but my search is still messed up and extremely slow (it takes a long time to output results)... Can anyone tell me what's going on?&lt;/P&gt;

&lt;P&gt;please help ;__;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Jul 2012 23:29:14 GMT</pubDate>
    <dc:creator>monicato</dc:creator>
    <dc:date>2012-07-13T23:29:14Z</dc:date>
    <item>
      <title>Messed up input data ruining/slowing down search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Messed-up-input-data-ruining-slowing-down-search/m-p/99097#M25581</link>
      <description>&lt;P&gt;Hi! &lt;/P&gt;

&lt;P&gt;I accidentally indexed really bizarre logs (partially downloaded logs)  and assigned it to a sourcetype. Now searches in this sourcetype is extremely slow and I get inconsistent and bizarre results. I then deleted them from my input directory but it seems like they still exist. Is there anyway to clear or erase the history?&lt;/P&gt;

&lt;P&gt;I used the  | delete command and it looks like it's gone, but my search is still messed up and extremely slow (it takes a long time to output results)... Can anyone tell me what's going on?&lt;/P&gt;

&lt;P&gt;please help ;__;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2012 23:29:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Messed-up-input-data-ruining-slowing-down-search/m-p/99097#M25581</guid>
      <dc:creator>monicato</dc:creator>
      <dc:date>2012-07-13T23:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Messed up input data ruining/slowing down search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Messed-up-input-data-ruining-slowing-down-search/m-p/99098#M25582</link>
      <description>&lt;P&gt;Not sure "what's going on?", but for you question in cleaning your "history", I assume you mean events/eventdata, this can be done by using the CLI command "&lt;CODE&gt;$SPLUNK_HOME/bin/splunk clean&lt;/CODE&gt;". Before using this, you should read the documentation, as you will lose ALL data in the indexes you choose to clean..&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/RemovedatafromSplunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Once you have cleaned a specific index (e.g. main), you may wish to re-index certain files that were previously monitored, as Splunk maintains a record of what it has indexed through CRC checks,etc, you may also need to look in to cleaning the fishbucket... BUT BE WARNED, this could result in duplicated data in other indexes.&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;MHIbbin&lt;/P&gt;</description>
      <pubDate>Sat, 14 Jul 2012 11:05:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Messed-up-input-data-ruining-slowing-down-search/m-p/99098#M25582</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-07-14T11:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Messed up input data ruining/slowing down search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Messed-up-input-data-ruining-slowing-down-search/m-p/99099#M25583</link>
      <description>&lt;P&gt;Thanks for the answer! I identified the source of the weird log and piped it to the delete command and that did the trick! No need to clear the index. Thanks for the help!&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2012 18:35:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Messed-up-input-data-ruining-slowing-down-search/m-p/99099#M25583</guid>
      <dc:creator>monicato</dc:creator>
      <dc:date>2012-07-16T18:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: Messed up input data ruining/slowing down search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Messed-up-input-data-ruining-slowing-down-search/m-p/99100#M25584</link>
      <description>&lt;P&gt;I did a 'clean' operation but the issue is still the same. &lt;BR /&gt;
Running a search query for the "last 15 minutes" takes more than 25 minutes to complete.&lt;BR /&gt;
Any ideas would be appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 08:37:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Messed-up-input-data-ruining-slowing-down-search/m-p/99100#M25584</guid>
      <dc:creator>wilsonchua</dc:creator>
      <dc:date>2016-01-15T08:37:54Z</dc:date>
    </item>
  </channel>
</rss>

