okay, this question can be read both ways. The search command
delete is no longer granted by default (this is the
delete_by_keyword capability btw) and must be assigned, also
delete does not actually delete raw data; it masks the data from showing up in search results.
To delete searches as local admin, using the Job monitor for example, one does not need any special capability.
Maybe the problem it the search head pooling over NFS, try the OS way from the docs to delete those searches http://docs.splunk.com/Documentation/Splunk/6.1.1/Knowledge/ManagejobsfromtheOS
Isn't that capability designed to give the ability to delete data from Splunk using the "delete" command? Per Splunk best practices, this capability should not normally be granted to any users, but instead should only temporarily be granted when specific data needs to be deleted.