Splunk Search

Accidentally deleted main index - Need help

chozha
New Member

I am new to splunk and while exploring tried the command index=main | delete.
Is there a way I can have the main index back without re-installing.

I have a Free license and don't want to end up losing the free license I have.

Tags (1)
0 Karma

woodcock
Esteemed Legend

You can open a support case and they have the tools to undelete your data but it will be easier just to forward it in again.

0 Karma

jacobpevans
Motivator

Greetings @chozha,

No need to worry, you did not delete the actual index with that command. What you did is you "deleted" all of the events in the main index. All you have to do is re-index whatever data you would like to play with.

Cheers,
Jacob

Cheers,
Jacob

If you feel this response answered your question, please do not forget to mark it as such. If it did not, but you do have the answer, feel free to answer your own post and accept that as the answer.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...