Getting Data In

how can I delete or archive old data

perlish
Communicator

There're 300G disk space in my server, how can I delete or archive old data in splunk ?
Thank you !

Tags (1)
0 Karma
1 Solution

DaveSavage
Builder

Check this out...and there is a rich thread on this subject in splunkbase. Just be careful especially around the time parameters!

http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/RemovedatafromSplunk

View solution in original post

DaveSavage
Builder

Check this out...and there is a rich thread on this subject in splunkbase. Just be careful especially around the time parameters!

http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/RemovedatafromSplunk

Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...