Getting Data In

How do you delete an index from a Splunk deployment with a non-clustered Indexer setup?

aknsun
Path Finder

Hi,

I would like to remove an index using the Splunk remove index command.

My environment has a non-clustered Indexer setup ( to be soon clustered), but with a Clustered SH deployment.

Can you let me know the Best Practice to delete an index for the above mentioned deployment?

Do I need to run the command on all Indexers?

Thanks,

AKN

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, you must remove the index from all indexers on which it is present.
It's not necessary, but is a good practice to also remove the index from your search heads. Do that by editing the indexes.conf file in the appropriate app on your SHC deployer, then deploy.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Yes, you must remove the index from all indexers on which it is present.
It's not necessary, but is a good practice to also remove the index from your search heads. Do that by editing the indexes.conf file in the appropriate app on your SHC deployer, then deploy.

---
If this reply helps you, Karma would be appreciated.

aknsun
Path Finder

@richgalloway . Thanks for the quick response.

0 Karma

aknsun
Path Finder

Hi,
@richgalloway
I still see reference to the deleted Index on the DMC under Settings-> Monitoring Console -> Indexing -> Indexes and Volumes-> "Indexes and Volumes: Deployment".
The Indexers have not been restarted after the Index removal. Neither has the DMC been restarted,

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...