Getting Data In

How to remove sources from disk via CLI?

Benlavender
Explorer

Hello,

We’re looking to remove data from one of our indexes, preferably using the clean operator from the CLI.

We have the some sources like “Perfmon:CPU Load” and “WinEventLog:System” – What would the correct clean syntax be to remove these sources from disk in the CLI be please?

Thanks

Tags (3)
0 Karma

yannK
Splunk Employee
Splunk Employee

There is no way to remove selectively data from a bucket/index.
you can only hide it using the "|delete" command
or delete all data with the "clean" command

Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...