Splunk Dev

how delete a data from an index

amyculquer
Explorer

I try to delete data but it does not work and show me this message Error in 'delete' command: You have insufficient privileges to delete events. So I create a user who has the the "delete_by_keyword" capability with the role can_delete but it does not work eigther.

Tags (1)

diogofgm
SplunkTrust
SplunkTrust

You have a role called "can_delete". Just add it to you user.

------------
Hope I was able to help you. If so, some karma would be appreciated.

amyculquer
Explorer

I did that, but it does not work

0 Karma

somesoni2
Revered Legend

You get the same error with your new role (which has can_delete capability)?

0 Karma

amyculquer
Explorer

Yes, I create the user named deleted which has the role of can_delete , this role is already enabled by keyword delete and still does not work and show me the error mensagge You have insufficient privileges to delete events.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...