Getting Data In

How to delete specific event?

ford1863
New Member

Hello,

How can I delete some specific event in Splunk? For example, one log loaded in splunk with 50 events, and I want to delete one or two events in them.

Tags (2)
0 Karma
1 Solution

Ayn
Legend

Use the delete operator.

http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Delete

Note that you need the can_delete privileged in order to be able to use this, and by default no roles (not even admin) have this privilege, so you'll need to add it before you can use this command.

View solution in original post

Ayn
Legend

Use the delete operator.

http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Delete

Note that you need the can_delete privileged in order to be able to use this, and by default no roles (not even admin) have this privilege, so you'll need to add it before you can use this command.

Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...