Deployment Architecture

How do I empty an index in an indexer cluster

nls7010
Path Finder

Clients wanted a change in how there data was displayed using the sourcetype they first used. How do I remove all of what they have currently indexed so we don't get duplicate entries?

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @nls7010,
in an Indexer Cluster, you could:

  • set to 1 the Retention Period (frozenTimePeriodInSecs = 1) for your index on Master Node,
  • push configurations to Peers,
  • wait 5 minutes,
  • set the Retention Periodto the value you like (frozenTimePeriodInSecs = your_value) for your index on Master Node,
  • push configurations to Peers.

Ciao.
Giuseppe

0 Karma

Anantha123
Communicator
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...