Deployment Architecture

How do I empty an index in an indexer cluster

nls7010
Path Finder

Clients wanted a change in how there data was displayed using the sourcetype they first used. How do I remove all of what they have currently indexed so we don't get duplicate entries?

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @nls7010,
in an Indexer Cluster, you could:

  • set to 1 the Retention Period (frozenTimePeriodInSecs = 1) for your index on Master Node,
  • push configurations to Peers,
  • wait 5 minutes,
  • set the Retention Periodto the value you like (frozenTimePeriodInSecs = your_value) for your index on Master Node,
  • push configurations to Peers.

Ciao.
Giuseppe

0 Karma

Anantha123
Communicator
0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...