Splunk IT Service Intelligence
Highlighted

What's a safe way to clear all ITSI notable events?

Path Finder

I am testing throttling/suppression on ITSI and would like to clear out the notables generated so far. Is this as simple as clearing them from index=itsitrackedalerts, or are there other cleanup tasks I should complete as well? If there's a published method I'm happy to read up on it myself, and thank you!

Highlighted

Re: What's a safe way to clear all ITSI notable events?

Explorer

to completely refresh and clean notable events , you can do the following (try this in test first, not prod) :

How to wipe all events from indexes and kvstores and start over

$SPLUNKHOME/bin/splunk stop
$SPLUNK
HOME/bin/splunk clean eventdata -index itsitrackedalerts;
$SPLUNKHOME/bin/splunk clean eventdata -index itsigroupedalerts;
$SPLUNK
HOME/bin/splunk start

$SPLUNKHOME/bin/splunk clean kvstore -app SA-ITOA -collection itsinotableeventgroup
$SPLUNKHOME/bin/splunk clean kvstore -app SA-ITOA -collection itsinotableeventstate
$SPLUNKHOME/bin/splunk clean kvstore -app SA-ITOA -collection itsinotableeventtag
$SPLUNKHOME/bin/splunk clean kvstore -app SA-ITOA -collection itsinotableeventcomment
$SPLUNKHOME/bin/splunk clean kvstore -app SA-ITOA -collection itsinotableeventticketing

Highlighted

Re: What's a safe way to clear all ITSI notable events?

Splunk Employee
Splunk Employee
0 Karma