Hi.
How to delete/clear all the indexed events,saved searches.How to make it brand new as it was after installing for the first time.
Any Suggestions are Appreciated,
Cheers.
1) The below command will not delete the indexed data from the Splunk , instead it doesn't show the results in splunk search.
index=* | delete
2) Below is the purge script - copt it to your splunk server and save as (script.sh). Specify your app names if you would like to delete your local configurations.
Execute with command : sh purge.sh
This will cleanup all the indexed data and your app local configurations
#!/bin/bash
clear
/opt/splunk/bin/splunk stop
/opt/splunk/bin/splunk clean eventdata
rm -rf /opt/splunk/etc/apps/Your_app_name1/local/*
rm -rf /opt/splunk/etc/apps/your_app_name2/local/*
/opt/splunk/bin/splunk start
1) The below command will not delete the indexed data from the Splunk , instead it doesn't show the results in splunk search.
index=* | delete
2) Below is the purge script - copt it to your splunk server and save as (script.sh). Specify your app names if you would like to delete your local configurations.
Execute with command : sh purge.sh
This will cleanup all the indexed data and your app local configurations
#!/bin/bash
clear
/opt/splunk/bin/splunk stop
/opt/splunk/bin/splunk clean eventdata
rm -rf /opt/splunk/etc/apps/Your_app_name1/local/*
rm -rf /opt/splunk/etc/apps/your_app_name2/local/*
/opt/splunk/bin/splunk start
Thank you.I just stopped splunk & deleted the folder.
stop splunk
cd splunk\bin\
splunk clean eventdata -index <index_name>
easiest way, stop splunk. Delete the index store folders. restart splunk
Hi i have installed Splunk on windows, how to delete the indexed data.