Getting Data In

How do I delete events?

the_wolverine
Champion

I have some data in my index that I don't want. How can I get rid of them?

Tags (3)
1 Solution

the_wolverine
Champion

You can search for your unwanted events and then pipe them to delete. For example:

sourcetype=wantedsource | delete

It's a good idea to search for your events first and confirm that these events are the correct events.

Important notes:

  • The user running this command must have the delete capability or be assigned the can_delete role.

  • This command does not reclaim disk space. It merely masks the deleted events so that they are not returned as part of search results. To reclaim disk space, you need to clean the index -- if all of your unwanted data is in one index then you can simply clean that index. Or, set an automatic archival policy to, eventually, expire your data automatically but then you'll have wait for the trigger (size or age.)

View solution in original post

dmaislin_splunk
Splunk Employee
Splunk Employee

FYI: You can only run the | delete command if you add the can_delete option in the role of the user.

tpaulsen
Contributor

Yes, that´s what was stated in the original answer already.

tpaulsen
Contributor

Will the deleted masked events age out as well?

0 Karma

the_wolverine
Champion

You can search for your unwanted events and then pipe them to delete. For example:

sourcetype=wantedsource | delete

It's a good idea to search for your events first and confirm that these events are the correct events.

Important notes:

  • The user running this command must have the delete capability or be assigned the can_delete role.

  • This command does not reclaim disk space. It merely masks the deleted events so that they are not returned as part of search results. To reclaim disk space, you need to clean the index -- if all of your unwanted data is in one index then you can simply clean that index. Or, set an automatic archival policy to, eventually, expire your data automatically but then you'll have wait for the trigger (size or age.)

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...