Getting Data In

Delete/clean all the contents of splunk

Contributor

Hi.

How to delete/clear all the indexed events,saved searches.How to make it brand new as it was after installing for the first time.

Any Suggestions are Appreciated,

Cheers.

0 Karma
1 Solution

Contributor

1) The below command will not delete the indexed data from the Splunk , instead it doesn't show the results in splunk search.
index=* | delete

2) Below is the purge script - copt it to your splunk server and save as (script.sh). Specify your app names if you would like to delete your local configurations.

Execute with command : sh purge.sh

This will cleanup all the indexed data and your app local configurations

#!/bin/bash
clear
/opt/splunk/bin/splunk stop
/opt/splunk/bin/splunk clean eventdata
rm -rf /opt/splunk/etc/apps/Your_app_name1/local/*
rm -rf /opt/splunk/etc/apps/your_app_name2/local/*
/opt/splunk/bin/splunk start

View solution in original post

Contributor

1) The below command will not delete the indexed data from the Splunk , instead it doesn't show the results in splunk search.
index=* | delete

2) Below is the purge script - copt it to your splunk server and save as (script.sh). Specify your app names if you would like to delete your local configurations.

Execute with command : sh purge.sh

This will cleanup all the indexed data and your app local configurations

#!/bin/bash
clear
/opt/splunk/bin/splunk stop
/opt/splunk/bin/splunk clean eventdata
rm -rf /opt/splunk/etc/apps/Your_app_name1/local/*
rm -rf /opt/splunk/etc/apps/your_app_name2/local/*
/opt/splunk/bin/splunk start

View solution in original post

Contributor

Thank you.I just stopped splunk & deleted the folder.

0 Karma

Champion

stop splunk

cd splunk\bin\
splunk clean eventdata -index <index_name>

easiest way, stop splunk. Delete the index store folders. restart splunk

0 Karma

Contributor

Hi i have installed Splunk on windows, how to delete the indexed data.

0 Karma