Getting Data In

Index cleared after disabling input?

StefanB
Explorer

Hello,

when I have configured an input for log files, ie from a certain directory, and I disable it any time, will my index get cleared of this information or is the information still in my index and searchable?

Tags (2)
0 Karma
1 Solution

Ayn
Legend

All information will still be in the index and searchable.

View solution in original post

Ayn
Legend

All information will still be in the index and searchable.

Ayn
Legend

You can clean a whole index by issuing "splunk clean -index " from the command line. If you want to remove only specific events you can use the "delete" operator. Note however that events affected by "delete" won't actually disappear from the index, rather they will only be hidden, so they will still take up disk space. Deleted events disappear when they're moved to the frozen bucket, though.

0 Karma

StefanB
Explorer

is there any way to clear the index then? or should i better be using different indexes then for every app?

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...