Getting Data In

How come some data returns after doing pipe delete and a restart of indexers?

dpanych
Communicator

We're having issues when we delete some data (with |delete) and after an indexer restarts in the clustered environment, some of the data replicated again. I did some research and found that this was a previous bug (SPL-100516). Has it been fixed?

s2_splunk
Splunk Employee
Splunk Employee

Which version of Splunk are you running?

0 Karma

dpanych
Communicator

We are running 6.4.1

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

This is a known issue that is being addressed by engineering.

s2_splunk
Splunk Employee
Splunk Employee

Current workaround:

5 minutes after executing the search which deletes events, manually execute:

$SPLUNK_HOME/bin/splunkd apply-delete-journals

on the indexes/buckets from which data was deleted.

coltwanger
Contributor

Why is this SPL not listed on the Known Issues page for the latest release?

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Not sure, but I am having that addressed by the docs team.

coltwanger
Contributor

Thank you!

0 Karma

dpanych
Communicator

Is there a workaround for deleting files and making sure they're gone?

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...