Getting Data In

How come some data returns after doing pipe delete and a restart of indexers?

dpanych
Communicator

We're having issues when we delete some data (with |delete) and after an indexer restarts in the clustered environment, some of the data replicated again. I did some research and found that this was a previous bug (SPL-100516). Has it been fixed?

s2_splunk
Splunk Employee
Splunk Employee

Which version of Splunk are you running?

0 Karma

dpanych
Communicator

We are running 6.4.1

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

This is a known issue that is being addressed by engineering.

s2_splunk
Splunk Employee
Splunk Employee

Current workaround:

5 minutes after executing the search which deletes events, manually execute:

$SPLUNK_HOME/bin/splunkd apply-delete-journals

on the indexes/buckets from which data was deleted.

coltwanger
Contributor

Why is this SPL not listed on the Known Issues page for the latest release?

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Not sure, but I am having that addressed by the docs team.

coltwanger
Contributor

Thank you!

0 Karma

dpanych
Communicator

Is there a workaround for deleting files and making sure they're gone?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...