In Splunk 7.1.2, when searching, it will suggest terms that have been indexed in the past. I have deleted some data, but the data is still showing in "matching terms" when i start typing in the search bar.
This does solve the problem in short-term. In my case, though, we accidentally ingested passwords in a file. We do not want this visible to anyone regardless of role, so we deleted it (| delete). We like the matching terms normally as it is convenient when searching something like "host=" to have the list of hosts, but right now if we type "password" it will show the deleted data's content. I'd like to type "password" but not show the deleted data's content; only new data.