Knowledge Management

splunk clean all problem

gjohnson
New Member

I have been trying to wipe out an eval instance of splunk to start again, but I keep getting errors. I then upgraded to the latest version of splunk and tried again. I tried stopping all splunk services and issuing the clean command while splunk was stopped and continue to get an error. I used to get a failure to wipe out the dirty_database, now I am getting an error: could not delete "d:\program files\splunk\var\log\splunk" there are no more files...

Short of completely uninstalling - any ideas?

Tags (1)
0 Karma

lukejadamec
Super Champion

Copy the db directories to a cd, so you can hang it on the wall later if things don't work out.

Reinstall Splunk.

Try to copy the db directories back to their original location. If that does not work, hang the cd on the wall as a reminder.

If you issued a clean command, then there is no usable date in the db directories, but the cd will not be empty, so it must be worth something.

If you followed best practice, and you have already deleted your data with clean, then save all .../local files, so you can restore them later.

My preference is to save the entire ...splunk/etc folder, just in case.

Splunk is powerful, but the real power is found in the custom configurations of splunk, which are found in .../splunk/etc/*.

Why have you not contacted splunk support?

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Based on what you are saying, if you don't care about the data, just wipe it out and re-install it. You'll have Splunk up and running in a couple of minutes rather than messing with the errors.

0 Karma

chrisknox
New Member

I did that, but it won't scale. I want to delete the data. Permanently. Irretrievably. To a point of metaphysical nonbeing. Yesterday's data does not matter. It's archived elsewhere. The CLEAN command seems to be locked away in a newbie-proof bottle.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...