Getting Data In

Problems Deleting Data in Splunk 6

conner9
Path Finder

Trying to delete data from an index for a specific day, and keep getting an error.

index=os sourcetype=ps provides 600k results for a single day.

index=os sourcetype=ps | delete results in "job terminated unexpectedly" "search terminated because of an error"

Yes the account has the delete functionality.

Thanks in advance for any thoughts.

Tags (2)
1 Solution

conner9
Path Finder

I found my particular problem. Some of the files in my index directory were owned by root, and it was preventing my deletes from taking affect. As soon as I reset ownership to splunk:splunk, it started working again.

View solution in original post

conner9
Path Finder

I found my particular problem. Some of the files in my index directory were owned by root, and it was preventing my deletes from taking affect. As soon as I reset ownership to splunk:splunk, it started working again.

jtrucks
Splunk Employee
Splunk Employee

Have you tried deleting data for only a couple hours or some other shorter period of time? It is possible you are hitting resource constraints that are messing with the completion of the job.

--
Jesse Trucks
Minister of Magic

conner9
Path Finder

I did, and it was still failing.

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...