Getting Data In

Deleted events still showing in search summary

hughroberts
Explorer

Hi all

I deleted a large number of events taken through a UniversalForwarder (v5.0.3) using the | delete command.

However these events are still showing up in the event counts on the Search summary page, they don't show up in a regular search only on the summary page.

Is there any way to fix these count totals?

Set up is clustered environment with 2 indexers, one cluster master and one search head, all servers are v5.0.3 running on Windows 2008.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

It can take some time (as much as an hour or so) for the metadata to be updated after a delete command.

hughroberts
Explorer

thanks for the tip, its been that way for 24 hours, think there is a bucket issue, am looking at doing a meta.dirty to force a rebuild of the metsdata.

ShaneNewman
Motivator

Is there a chance you have used search optimization? If you have, splunk creates a summary index, meaning the historical data will still be in that summary index.

0 Karma

hughroberts
Explorer

hmmmm, should not be on for that specific index but its a possible, thanks for the tip, its give me some things to investigate

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...