Splunk Enterprise

How to remove some indexed data

volkergersabeck
New Member

Hi,

we're using the free license of splunk and are very happy with it. Unfortunately, our application ran into this bug (https://issues.apache.org/bugzilla/show_bug.cgi?id=44178) which caused our search index to be flooded with exception logs. Due to that our search is now disabled because the splunk index is too large. Is there a way to delete these exceptions from the index to bring it below the limit again? Since I don't want to loose the other logs I can't delete the complete index. I can't use the delete command in the search, because the search is disabled due to the license violation.

Is there any way to do this?

Thanks

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Deleting the data (even if you could) will not reset the license. The violation is not based on the amount of data in the index, but on how much was indexed during the day, and that can not be undone. You can clear the violation only by cleaning all the data, a license reset key, or waiting until after the window has passed.

RicoSuave
Builder

yes, run a search that will return only those events and just pipe it to delete. Assuming you have the can_delete permissions, this should work

example: mysearch | delete

gkanapathy
Splunk Employee
Splunk Employee

It also doesn't matter if you delete the data. The license violation is not based on how much data is in the index, but how much was indexed during the day. That has already occurred. The only ways to clear the violation are to completely delete all the data ("./splunk clean all"), install a license reset key, or wait until the violations are outside of the rolling 30-day window.

volkergersabeck
New Member

Because of the license violation I'm not able to run a search. That's why I'm unable to delete the data. I'm using the admin user, so I guess I have the permission set, but the search itself doesn't work.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...