Deployment Architecture

Flush all logs in indexes

pdash
Path Finder

I want to flush all the logs in my indexes in splunk server.
I am stopping the splunk process
And then doing splunk clean eventdata
But even though it shows all cleaned when i restart splunk I see hot_v1_9 folder still in the db.
How do I flush every log in the index?

Tags (1)
0 Karma

Drainy
Champion

Does the hot_v1_9 folder have a particularly large size? Splunk will create a new hot bucket as it starts for an active index and if there is any data for it.

Drainy
Champion

Take a backup first but if you stop Splunk and delete the folder so no buckets exist it should create them as needed.

0 Karma

pdash
Path Finder

yes its around 1.2G. So will it affect if i delete these folders? I dont need the indexed data anyways.

0 Karma
Get Updates on the Splunk Community!

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...

Stay Connected: Your Guide to October Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...