Hi
I would like to delete an index. This will be my first time, so I do not want to do to much harm.
-Is there any obstacle?
-What is the best way to do that?
-About what I need to remember?
or maybe I could remove data if I do not have any extracted fields?
Thank you
In summary:
First you'll want to ensure that any inputs that are sending events to that index are disabled. This way the indexer won't be confused while it keeps receiving events for a deleted index.
Next, delete or comment out any configuration in indexes.conf associated with this index.
Finally, restart the indexer ( or apply cluster-bundle for indexer cluster ) and then delete the directory the index is associated with.
More details here : http://docs.splunk.com/Documentation/Splunk/6.3.0/Indexer/RemovedatafromSplunk
Some reading available here
link is very useful. Thank you.
Last question:
if I go to Settings - Inexes. There I see Actions "DELETE" available next to indexes which have been created. This has not been mentioned on documentation
Can I use it ? What is the drowback of that way?
In summary:
First you'll want to ensure that any inputs that are sending events to that index are disabled. This way the indexer won't be confused while it keeps receiving events for a deleted index.
Next, delete or comment out any configuration in indexes.conf associated with this index.
Finally, restart the indexer ( or apply cluster-bundle for indexer cluster ) and then delete the directory the index is associated with.
More details here : http://docs.splunk.com/Documentation/Splunk/6.3.0/Indexer/RemovedatafromSplunk
link is very useful. Thank you.
Last question:
Currently I have just flat files.
if I go to Settings - Inexes. There I see Actions "DELETE" available next to indexes which have been created. This has not been mentioned on documentation
Can I use it ? What is the drowback of that way?