Getting Data In

Index cleared after disabling input?

StefanB
Explorer

Hello,

when I have configured an input for log files, ie from a certain directory, and I disable it any time, will my index get cleared of this information or is the information still in my index and searchable?

Tags (2)
0 Karma
1 Solution

Ayn
Legend

All information will still be in the index and searchable.

View solution in original post

Ayn
Legend

All information will still be in the index and searchable.

Ayn
Legend

You can clean a whole index by issuing "splunk clean -index " from the command line. If you want to remove only specific events you can use the "delete" operator. Note however that events affected by "delete" won't actually disappear from the index, rather they will only be hidden, so they will still take up disk space. Deleted events disappear when they're moved to the frozen bucket, though.

0 Karma

StefanB
Explorer

is there any way to clear the index then? or should i better be using different indexes then for every app?

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...