I recently upgraded to 4.1.2 from 3.4.x. I needed to remove several hosts from our index, so I followed the instructions at http://www.splunk.com/base/Documentation/4.1.1/Admin/RemovedatafromSplunk. It worked fine, except that now I have several hosts listed on the dashboard with zero events. I also have a saved search that alerts on failed forwarders, and the zero event hosts are triggering this. How can I remove them completely? With version 3.4.x I didn't encounter this problem when using oldsearch to remove events.
They are likely stuck in old metadata, where the bucket needs to be optimized. I suggest you first try to alter your search to workaround the problem. Secondly, when your deleted data gets frozen/deleted, this problem will go away.
The reason why you are probably seeing this, is that the metadata still exists for that host. It's possible it is a bug, but there are ways to check why this is occurring. You may want to run the following search to see if it is a metadata problem: