Getting Data In

Deleted events still showing in search summary

hughroberts
Explorer

Hi all

I deleted a large number of events taken through a UniversalForwarder (v5.0.3) using the | delete command.

However these events are still showing up in the event counts on the Search summary page, they don't show up in a regular search only on the summary page.

Is there any way to fix these count totals?

Set up is clustered environment with 2 indexers, one cluster master and one search head, all servers are v5.0.3 running on Windows 2008.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

It can take some time (as much as an hour or so) for the metadata to be updated after a delete command.

hughroberts
Explorer

thanks for the tip, its been that way for 24 hours, think there is a bucket issue, am looking at doing a meta.dirty to force a rebuild of the metsdata.

ShaneNewman
Motivator

Is there a chance you have used search optimization? If you have, splunk creates a summary index, meaning the historical data will still be in that summary index.

0 Karma

hughroberts
Explorer

hmmmm, should not be on for that specific index but its a possible, thanks for the tip, its give me some things to investigate

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...