Splunk Version: 6.1.2 (Free Edition)
OS: Mac OS X 10.10.2
How can I remove eventdata even if splunk restarts ?
I tried to remove all of indexed event data, with following commands
pollux:splunk ohisa$ pwd
pollux:splunk ohisa$ /Applications/Splunk/bin/splunk stop
Shutting down. Please wait, as this may take a few minutes.
Stopping splunk helpers...
Checking http port : open
Checking mgmt port : open
Checking appserver port [127.0.0.1:8065]: open
Checking kvstore port : open
Checking configuration... Done.
Checking critical directories... Done
Validated: _audit _blocksignature _internal _introspection _thefishbucket history main summary
Checking filesystem compatibility... Done
Checking conf files for problems...
All preliminary checks passed.