Deployment Architecture

Why am able to see events even after deleting them from GUI?

siva_cg
Path Finder

Hi All,

We have a multisite clustered environment with 24 indexers and 8 search heads and all servers are running with 6.5.2 version.

We are deleting some of the events from Search Head GUI using delete command. But in the next day, we are able to see the events with the same query from GUI. Is there any reason why I am able to see the logs even after deleting from GUI?

Thanks in advance.

0 Karma
1 Solution

elliotproebstel
Champion

We had this same issue, and it persisted until we did a rolling restart of all indexers. We filed a Splunk support ticket, and that's the advice we were given. It was unsatisfying, but it worked.

View solution in original post

jhornsby
Splunk Employee
Splunk Employee

There are a number of issues with the way that |delete works in an indexer cluster in 6.5.2. You might want to upgrade to 6.5.4, which contains fixes for SPL-100516/SPL-136735 [Events deleted in an index cluster via the delete search operator may be inconsistently deleted on secondaries] and SPL-140333 [Disappearing cold bucket directories can wedge IndexerService thread (and others) while calculating bucket checksums].

0 Karma

elliotproebstel
Champion

We had this same issue, and it persisted until we did a rolling restart of all indexers. We filed a Splunk support ticket, and that's the advice we were given. It was unsatisfying, but it worked.

siva_cg
Path Finder

Thank you @elliotproebstel.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...