Deployment Architecture

Flush all logs in indexes

pdash
Path Finder

I want to flush all the logs in my indexes in splunk server.
I am stopping the splunk process
And then doing splunk clean eventdata
But even though it shows all cleaned when i restart splunk I see hot_v1_9 folder still in the db.
How do I flush every log in the index?

Tags (1)
0 Karma

Drainy
Champion

Does the hot_v1_9 folder have a particularly large size? Splunk will create a new hot bucket as it starts for an active index and if there is any data for it.

Drainy
Champion

Take a backup first but if you stop Splunk and delete the folder so no buckets exist it should create them as needed.

0 Karma

pdash
Path Finder

yes its around 1.2G. So will it affect if i delete these folders? I dont need the indexed data anyways.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...