Deployment Architecture

Deleting distinct data from index

iKate
Builder

Hello,
Can someone explain why there is no inbuilt functionality of deleting just some indexed data - from particular source or for particular date etc? Are there still not enough requests for this feature?

I know that it's better to create different indexes, but it's weird to make separate index for each search.
Importing to csv, editing and then reindexing as I've read is correlated with high risks.
Just hiding results from searches by "delete" won't move the data.
Cleaning entire index isn't a decision when lots of searches have already been indexed in it.

So can you please answer why is it so? And is it going to be solved?

Thanks

Tags (2)
0 Karma

mjhennig
Engager

Maybe this answer could help: http://splunk-base.splunk.com/answers/62516/delete-the-data-after-indexing -- Although it's still weird somehow, because one needs to stop the Splunk daemon before the operation..

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...