Splunk Cloud Platform

Deleting events/index on Cloud, what actually happens?

marchias
Observer

I'm confused on some of the differences between Cloud and Enterprise. Sometimes the documentation on Cloud does not go far enough to define those differences and one of them is the for Deletion of Events/Indexes. If I use the Splunk UI Web and delete an index is it "marked" as deleted like Enterprise where it is just hidden from Search or is it physically deleted on Cloud? Also if I use the sourcetype=wantedsource | delete approach on the search head, same question. 

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

For 1st one I suppose that they also remove the removed index, but how fast it will happen, I don't know. I think that only SC operation/architect staff will know exact answer for this and they probably don't tell it ;-(

For 2nd one I believe that it works just like in on prem. Splunk just marks those events as deleted, but don't remove those from disk/index/bucket before that bucket has removed.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...