Deployment Architecture

Deleting distinct data from index

iKate
Builder

Hello,
Can someone explain why there is no inbuilt functionality of deleting just some indexed data - from particular source or for particular date etc? Are there still not enough requests for this feature?

I know that it's better to create different indexes, but it's weird to make separate index for each search.
Importing to csv, editing and then reindexing as I've read is correlated with high risks.
Just hiding results from searches by "delete" won't move the data.
Cleaning entire index isn't a decision when lots of searches have already been indexed in it.

So can you please answer why is it so? And is it going to be solved?

Thanks

Tags (2)
0 Karma

mjhennig
Engager

Maybe this answer could help: http://splunk-base.splunk.com/answers/62516/delete-the-data-after-indexing -- Although it's still weird somehow, because one needs to stop the Splunk daemon before the operation..

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...