Splunk Enterprise

How to clean / delete logs from _internaldb and _introspection indexes

GaetanVP
Contributor

Hello Splunkers, 

My _internaldb and _introspection indexes are getting bigger and I am wondering if I can delete some events in order to reduce their sizes ? How would I do that ? Is it safe to do it ? 

Thanks for your time !

GaetanVP

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you could set retention times etc. as any other indexes have. I prefer to use separate app/SA which contains these definitions. Then just install it on your indexer or via cluster master.

r. Ismo

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...