I'm confused on some of the differences between Cloud and Enterprise. Sometimes the documentation on Cloud does not go far enough to define those differences and one of them is the for Deletion of Events/Indexes. If I use the Splunk UI Web and delete an index is it "marked" as deleted like Enterprise where it is just hidden from Search or is it physically deleted on Cloud? Also if I use the sourcetype=wantedsource | delete approach on the search head, same question.
Hi
For 1st one I suppose that they also remove the removed index, but how fast it will happen, I don't know. I think that only SC operation/architect staff will know exact answer for this and they probably don't tell it ;-(
For 2nd one I believe that it works just like in on prem. Splunk just marks those events as deleted, but don't remove those from disk/index/bucket before that bucket has removed.
r. Ismo