- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
michael_lee
Path Finder
05-12-2015
06:35 AM
hi,
I have a monitored directory that is indexed by splunk. I tried removing the files in the directory after they are indexed. Restarted the splunk daemon and I still see the file contents when searched. My question is, can I confirm that I can safely remove those files in that directory that are already indexed without any other consequences ?
thanks
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
05-12-2015
06:58 AM
Once files are indexed then data remains in Splunk until it ages out. You no longer need the source file.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
05-12-2015
06:58 AM
Once files are indexed then data remains in Splunk until it ages out. You no longer need the source file.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
