Getting Data In

How to delete data in an index from a certain host?

PIETRO_CENTANNI
New Member

Hi

I have a need to save space on an indexer server.

In the main index, I have a data from a host that is not used and I would like to delete all of its data from the index.

How can I delete data only from this host without deleting everything in the main index? I want to delete the data, not hide it.

Thanks

0 Karma
1 Solution

renjith_nair
Legend

Hello @PIETRO_CENTANNI ,

Unfortunately, "splunk clean" is unable to delete specific data from index. It's all-or-nothing : The entire index has to be wiped, or none of it.
Instead you can set the retention period in Splunk for the particular index and delete old events to free up some space (frozenTimePeriodInSecs).

See
http://docs.splunk.com/Documentation/Splunk/6.0.2/Indexer/Setaretirementandarchivingpolicy
https://wiki.splunk.com/Deploy:BucketRotationAndRetention

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

Hello @PIETRO_CENTANNI ,

Unfortunately, "splunk clean" is unable to delete specific data from index. It's all-or-nothing : The entire index has to be wiped, or none of it.
Instead you can set the retention period in Splunk for the particular index and delete old events to free up some space (frozenTimePeriodInSecs).

See
http://docs.splunk.com/Documentation/Splunk/6.0.2/Indexer/Setaretirementandarchivingpolicy
https://wiki.splunk.com/Deploy:BucketRotationAndRetention

---
What goes around comes around. If it helps, hit it with Karma 🙂

PIETRO_CENTANNI
New Member

I have already a policy retention the I can't modify.
So the unique solution is add space.

Thank you and have a nice day

0 Karma

fdi01
Motivator

use clean command in splunk to do it.
from splunk_home/splunk/bin/ repertory in CLI,
run ./splunk help clean to understans how clean command work.
like this :

./splunk clean eventdata -index  your_index_name -f
0 Karma

PIETRO_CENTANNI
New Member

This command delete all index. I have need delete a single host from index.

0 Karma

klsio
Explorer

Using this command.

index='foo' | delete

0 Karma

woodcock
Esteemed Legend

This command does not actually delete anything; it just hides it. Therefore, there is no impact upon disk space.

0 Karma

klsio
Explorer

ah.. thank you 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...