Getting Data In

delete metrics data


I am trying to figure out how to delete metrics data. "| delete" doesn't work with mstats, is there another way?




You have to clear out the whole index (bin\splunk clean eventdata ...), or, more unsafely, delete the buckets/directories from the file system containing the bad data.

As of now, there is no supporting of the delete command. See my rantings here:

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!