Getting Data In

Index cleared after disabling input?

StefanB
Explorer

Hello,

when I have configured an input for log files, ie from a certain directory, and I disable it any time, will my index get cleared of this information or is the information still in my index and searchable?

Tags (2)
0 Karma
1 Solution

Ayn
Legend

All information will still be in the index and searchable.

View solution in original post

Ayn
Legend

All information will still be in the index and searchable.

Ayn
Legend

You can clean a whole index by issuing "splunk clean -index " from the command line. If you want to remove only specific events you can use the "delete" operator. Note however that events affected by "delete" won't actually disappear from the index, rather they will only be hidden, so they will still take up disk space. Deleted events disappear when they're moved to the frozen bucket, though.

0 Karma

StefanB
Explorer

is there any way to clear the index then? or should i better be using different indexes then for every app?

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...