Splunk Cloud Platform

Deleting events/index on Cloud, what actually happens?

marchias
Observer

I'm confused on some of the differences between Cloud and Enterprise. Sometimes the documentation on Cloud does not go far enough to define those differences and one of them is the for Deletion of Events/Indexes. If I use the Splunk UI Web and delete an index is it "marked" as deleted like Enterprise where it is just hidden from Search or is it physically deleted on Cloud? Also if I use the sourcetype=wantedsource | delete approach on the search head, same question. 

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

For 1st one I suppose that they also remove the removed index, but how fast it will happen, I don't know. I think that only SC operation/architect staff will know exact answer for this and they probably don't tell it ;-(

For 2nd one I believe that it works just like in on prem. Splunk just marks those events as deleted, but don't remove those from disk/index/bucket before that bucket has removed.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...