Getting Data In

Delete/clean all the contents of splunk

harshavrath
Contributor

Hi.

How to delete/clear all the indexed events,saved searches.How to make it brand new as it was after installing for the first time.

Any Suggestions are Appreciated,

Cheers.

0 Karma
1 Solution

chimbudp
Contributor

1) The below command will not delete the indexed data from the Splunk , instead it doesn't show the results in splunk search.
index=* | delete

2) Below is the purge script - copt it to your splunk server and save as (script.sh). Specify your app names if you would like to delete your local configurations.

Execute with command : sh purge.sh

This will cleanup all the indexed data and your app local configurations

#!/bin/bash
clear
/opt/splunk/bin/splunk stop
/opt/splunk/bin/splunk clean eventdata
rm -rf /opt/splunk/etc/apps/Your_app_name1/local/*
rm -rf /opt/splunk/etc/apps/your_app_name2/local/*
/opt/splunk/bin/splunk start

View solution in original post

chimbudp
Contributor

1) The below command will not delete the indexed data from the Splunk , instead it doesn't show the results in splunk search.
index=* | delete

2) Below is the purge script - copt it to your splunk server and save as (script.sh). Specify your app names if you would like to delete your local configurations.

Execute with command : sh purge.sh

This will cleanup all the indexed data and your app local configurations

#!/bin/bash
clear
/opt/splunk/bin/splunk stop
/opt/splunk/bin/splunk clean eventdata
rm -rf /opt/splunk/etc/apps/Your_app_name1/local/*
rm -rf /opt/splunk/etc/apps/your_app_name2/local/*
/opt/splunk/bin/splunk start

harshavrath
Contributor

Thank you.I just stopped splunk & deleted the folder.

0 Karma

linu1988
Champion

stop splunk

cd splunk\bin\
splunk clean eventdata -index <index_name>

easiest way, stop splunk. Delete the index store folders. restart splunk

0 Karma

harshavrath
Contributor

Hi i have installed Splunk on windows, how to delete the indexed data.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...