Getting Data In

How come some data returns after doing pipe delete and a restart of indexers?

dpanych
Communicator

We're having issues when we delete some data (with |delete) and after an indexer restarts in the clustered environment, some of the data replicated again. I did some research and found that this was a previous bug (SPL-100516). Has it been fixed?

s2_splunk
Splunk Employee
Splunk Employee

Which version of Splunk are you running?

0 Karma

dpanych
Communicator

We are running 6.4.1

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

This is a known issue that is being addressed by engineering.

s2_splunk
Splunk Employee
Splunk Employee

Current workaround:

5 minutes after executing the search which deletes events, manually execute:

$SPLUNK_HOME/bin/splunkd apply-delete-journals

on the indexes/buckets from which data was deleted.

coltwanger
Contributor

Why is this SPL not listed on the Known Issues page for the latest release?

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Not sure, but I am having that addressed by the docs team.

coltwanger
Contributor

Thank you!

0 Karma

dpanych
Communicator

Is there a workaround for deleting files and making sure they're gone?

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...