I am trying to figure out how to delete metrics data. "| delete" doesn't work with mstats, is there another way?
You have to clear out the whole index (bin\splunk clean eventdata ...), or, more unsafely, delete the buckets/directories from the file system containing the bad data.
bin\splunk clean eventdata ...
As of now, there is no supporting of the delete command. See my rantings here: https://answers.splunk.com/answers/579720/should-metrics-indexes-support-overwriting-events-1.html