We have a dataset that we hid from the index via a "| delete" command, but we need the data purged from disk as well, without removing the still searchable portions of the index.
Is the data just frozen and we can use the frozen expiration features to remove? Something else?
Any suggestions on how to purge out this old data?
You can use Splunk's regular data purging methods, either by size or by age. However, that will remove the oldest buckets first.
You can use Splunk's regular data purging methods, either by size or by age. However, that will remove the oldest buckets first.