Getting Data In

How to delete specific event?

ford1863
New Member

Hello,

How can I delete some specific event in Splunk? For example, one log loaded in splunk with 50 events, and I want to delete one or two events in them.

Tags (2)
0 Karma
1 Solution

Ayn
Legend

Use the delete operator.

http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Delete

Note that you need the can_delete privileged in order to be able to use this, and by default no roles (not even admin) have this privilege, so you'll need to add it before you can use this command.

View solution in original post

Ayn
Legend

Use the delete operator.

http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Delete

Note that you need the can_delete privileged in order to be able to use this, and by default no roles (not even admin) have this privilege, so you'll need to add it before you can use this command.

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...