Getting Data In

How to delete specific event?

ford1863
New Member

Hello,

How can I delete some specific event in Splunk? For example, one log loaded in splunk with 50 events, and I want to delete one or two events in them.

Tags (2)
0 Karma
1 Solution

Ayn
Legend

Use the delete operator.

http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Delete

Note that you need the can_delete privileged in order to be able to use this, and by default no roles (not even admin) have this privilege, so you'll need to add it before you can use this command.

View solution in original post

Ayn
Legend

Use the delete operator.

http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Delete

Note that you need the can_delete privileged in order to be able to use this, and by default no roles (not even admin) have this privilege, so you'll need to add it before you can use this command.

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...