Getting Data In

Deleting data from summary index or any index?

asingla
Communicator

I am summarizing my data every minute but I do not need that data after one hour. So I have schedule another search to run every hour to delete this old data. But I am realizing it is not freeing up the disk space. Am I missing anything? Do I need to do something more than just calling the | delete command?

Tags (1)
0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

The delete search command is only a "soft" delete ie: marks events as being deleted.
To do a hard delete, you need to delete the index or roll it off to frozen bucket with an aggressive frequency.

View solution in original post

0 Karma

Damien_Dallimor
Ultra Champion

The delete search command is only a "soft" delete ie: marks events as being deleted.
To do a hard delete, you need to delete the index or roll it off to frozen bucket with an aggressive frequency.

0 Karma

RicoSuave
Builder

Please look at the answer posted here.

http://splunk-base.splunk.com/answers/1484/how-do-i-delete-events

Deleting events does not reclaim disk space.

Get Updates on the Splunk Community!

What's New in Splunk Observability - November 2025

Feature Highlight  Analyze your dimensions and metrics with Usage Analytics  To help optimize telemetry data ...

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...