Getting Data In

Remove Index Command Not Working

katzr
Path Finder

Hello,

I am looking to remove an index entirely. I ran the search "splunk remove index new_hires" where new_hires is the index name. This command did not remove the index. I have the ability to delete. Why didn't this command work? I am using splunk 6.3.3. I want to remove the entire index and all associated data. Thank you!

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @katzr, here's documentation to remove indexes and indexed data. http://docs.splunk.com/Documentation/Splunk/6.6.2/Indexer/RemovedatafromSplunk#Remove_an_index_entir... It has that CLI command but has a step beforehand directing you make sure no inputs.conf are directing data to the index you plan to delete.

0 Karma

katzr
Path Finder

yes- there are none and I didn't get a warning message that there are any.

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Are you using the [http://docs.splunk.com/Documentation/Splunk/latest/Admin/AbouttheCLI?r=searchtip[ (CLI)? Verifying due to your usage of "ran the search".

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

If so, refer to @kmorris's detailed explanation above! 🙂

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

Do you have multiple indexers?

kmorris_splunk
Splunk Employee
Splunk Employee

I just noticed that you "ran the search" to remove the index. This is actually a command you would need to run via the CLI. Are you the administrator of the Splunk instance? If this is a single server instance (meaning you downloaded from splunk.com and installed it), then you should be able to remove the index from the GUI. However, if it is a distributed environment (meaning a separate search head, and multiple indexers, then the index would need to be removed from each indexer, via command line, using the command you typed in the search bar it seems.

katzr
Path Finder

no I don't believe so- is there anywhere I can check to make sure I don't.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

The delete command deletes event data from subsequent searches. It does not remove it from disk.

To remove data permanently from an index, use the CLI clean command.

See Remove indexes and indexed data in the Managing Indexers and Clusters of Indexers manual.

katzr
Path Finder

Do I need to clean the data before removing the entire index?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...

Index This | What is feather-light but cannot be held long?

May 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

.conf26 Registration is Live: Secure Your Early Bird Pass Now

  Lock in Your Spot: Registration Open for .conf26 in Denver Hello Splunkers, I have exciting news! Your ...