I'm looking for a possibility to delete all eventdata of one index at a specific time on every day! It is not important to use the "splunk clean eventdata -index" command. It can also be just an "search index = any |delete".
Whats the best method to get this working?
Yes I really need to delete every day.
Thanks the scheduled search is good idea and it should work for this situation. The cron job is difficult because you need to stop splunk for clean eventdata.