Getting Data In

When I delete an old version of Splunk does it delete the old indexes and hosts?

ellissa
New Member

Hi All,
I've recently had to reinstall Splunk on my server.
It was using an index called "index2", I've since removed that version of Splunk (which I thought would of deleted the index) and installed Splunk v7.

It's worth noting that I had about 10-12 forwarders sending syslog data to my Splunk instance before uninstalling.
Since installing the new Splunk v7 I can only see one available forwarder when selecting "add data"

The odd thing is that when I go to search and reporting and select index="newindex" it generates a whole lot of data and tells me I have 6 hosts contributing data.

This is quite puzzling. The IP address and port of the Splunk instance is exactly the same, so I'm not sure why they don't appear in the forwarder list under 'add data'

Appreciate any help i can get

S.

0 Karma

cmerriman
Super Champion

did you follow the Uninstall instructions?
https://docs.splunk.com/Documentation/Splunk/7.0.0/Installation/UninstallSplunk
If you had any indexes that didn't use the default path, those must be deleted also. This document includes a lot of good information in case you may have overlooked something in the uninstallation.

In that same doc, you can navigate to the Install Splunk on Windows/Linux (depending on which OS you're using) page and follow those instructions.

If you have followed these directions to a tee, have you tried adding your other forwarders and/or configuring the inputs that are already there?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...