Getting Data In

Deleting data from summary index or any index?

asingla
Communicator

I am summarizing my data every minute but I do not need that data after one hour. So I have schedule another search to run every hour to delete this old data. But I am realizing it is not freeing up the disk space. Am I missing anything? Do I need to do something more than just calling the | delete command?

Tags (1)
0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

The delete search command is only a "soft" delete ie: marks events as being deleted.
To do a hard delete, you need to delete the index or roll it off to frozen bucket with an aggressive frequency.

View solution in original post

0 Karma

Damien_Dallimor
Ultra Champion

The delete search command is only a "soft" delete ie: marks events as being deleted.
To do a hard delete, you need to delete the index or roll it off to frozen bucket with an aggressive frequency.

0 Karma

RicoSuave
Builder

Please look at the answer posted here.

http://splunk-base.splunk.com/answers/1484/how-do-i-delete-events

Deleting events does not reclaim disk space.

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...