http://docs.splunk.com/Documentation/Splunk/latest/admin/RemovedatafromSplunk
Example
./splunk clean eventdata -index yourindex
http://docs.splunk.com/Documentation/Splunk/latest/admin/RemovedatafromSplunk
Example
./splunk clean eventdata -index yourindex
DANGER - I hope you realize that performing a clean eventdata removes ALL events from the index. I know it's fairly obvious from both the command name and the description in the docs, but it's worth repeating.
If you use the delete
operator there is no way to physically remove the events, they will however be removed when cold buckets are moved to frozen.
Yes...command prompt. Those are linux examples. Go to to
splunk clean eventdata -index yourindex
thanks for quick reply.
i dont quite understand how to use CLI in splunk. im doing everything using websplunk only. currently my data are all local on a pc.
so, just to clarify...
CLI is only accessible via Command prompt on windows.
And then going to the directory $SPLUNKHOME/bin/
then doing the steps shown in ur link?
many thanks!