Splunk Search

How to delete data based on search results in 3.4.14 for Windows?

straffin
Explorer

I'd like to remove all data that matches a given search from my Splunk 3.4.14 for Windows install. I've found Windows-centric examples for earlier versions that don;t work for 3.4.14 (at http://www.splunk.com/base/Documentation/3.1.3/Admin/DeleteDataFromTheIndex) and 3.4.14-centric examples that don't work under Windows (at http://www.splunk.com/base/Documentation/3.4.14/Admin/RemoveDeleteData)

Anyone know what I need to do to delete indexed data based on search results in 3.4.14 for Windows?

Tags (3)
0 Karma

straffin
Explorer

I tried replacing the single-quotes with double-quotes...

C:\Program Files\Splunk\bin>splunk search " | oldsearch delete::sourcetype::WinRegistry"

... and it appears to be working fine.

(There was an error at the end about exceeding the maximum time limit, but it worked nonetheless.)

straffin
Explorer

Well now I feel like a total newb. 😕 After trying some other things, I had simply tried the command as listed in the 3.4.14-centric article listed above and, when it failed, I (in frustration) moved on to more searching and asking here. Just now, I tried replacing the single-quotes with double-quotes...

C:\Program Files\Splunk\bin>splunk search " | oldsearch delete::sourcetype::WinRegistry"

... and it appears to be working fine. Thanks for the encouragement to look at it again, anyway. 🙂

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Please indicate exactly what you typed in Windows, and what error you received. While http://www.splunk.com/base/Documentation/3.4.14/Admin/RemoveDeleteData#Remove_events_from_search_res... shows a non-Windows example, but the functionality will be identical, though of course as noted there you will have to correct the shell syntax (in particular directory separators and quotes) for it to work.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...