Splunk Enterprise

How to safely delete collection data?


Hey Splunk Community,

I'm having an issue with the $SPLUNK/var/lib/splunk/kvstore/mongo directory.

I have a tonne of files present in this directory dated from several months ago at around the 512MB size range ending in ".ns" and ".0". 

If we remove these files over say an age of 30 days would this have any impact on the SIEM or if this action safe?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Announcing General Availability of Splunk Incident Intelligence!

Digital transformation is real! Across industries, companies big and small are going through rapid digital ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...