Splunk Search

How can I update the metadata ?

cogrunc
New Member

Hello,
I deleted the redundant logs from an index with "delete" command. Now, I would like to update the metadata info. Is it possible?

Tags (1)
0 Karma
1 Solution

somesoni2
Revered Legend

From the link , the delete command doesn't update the metadata. There is no direct method to update the metadata. The workaround will be do a re-indexing of the data which in most cases is not feasible.

http://answers.splunk.com/answers/2031/remove-hostname-from-the-metadata.html

View solution in original post

somesoni2
Revered Legend

From the link , the delete command doesn't update the metadata. There is no direct method to update the metadata. The workaround will be do a re-indexing of the data which in most cases is not feasible.

http://answers.splunk.com/answers/2031/remove-hostname-from-the-metadata.html

martin_mueller
SplunkTrust
SplunkTrust

Just let the "wrong" buckets age out, it'll fix itself over the retention period for that index.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...