Other Usage

How do you delete a default index?

erikhill
Explorer


This page states: 

You can't delete default indexes and third-party indexes from the Indexes page. 

 

Can I still delete default indexes through the CLI?

 

0 Karma
1 Solution

inventsekar
SplunkTrust
SplunkTrust

Hi @erikhill 

That doc is for "Splunk Cloud"(CLI access is with Splunk Cloud Support Team) and from the GUI page you can not delete.

For Splunk Enterprise, i tried it on my lab setup:


C:\Program Files\Splunk\bin>.\splunk.exe remove index main
WARNING: Server Certificate Warning - ignore this

cannot remove idx=main, is internal

C:\Program Files\Splunk\bin>

 

so, we can not remove the default index(es), thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

View solution in original post

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @erikhill 

That doc is for "Splunk Cloud"(CLI access is with Splunk Cloud Support Team) and from the GUI page you can not delete.

For Splunk Enterprise, i tried it on my lab setup:


C:\Program Files\Splunk\bin>.\splunk.exe remove index main
WARNING: Server Certificate Warning - ignore this

cannot remove idx=main, is internal

C:\Program Files\Splunk\bin>

 

so, we can not remove the default index(es), thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @erikhill  may i know if the above reply solves your query, if not, pls let us know more details. 

if yes, could you pls accept it as solution, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

erikhill
Explorer

I appreciate the response @inventsekar , thank you.  I have a main index that I don't need anymore and I'd like to remove. If the index can't be deleted, can all of the data be removed from the index?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

If you already ingested some data into this index and you don't need/want it in your instance anymore you can set a short retention period so that data is quickly rolled out and removed from the index. It's the easiest and most elegant way.

erikhill
Explorer

Great! Thanks @PickleRick , I'll give that a shot!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...