Splunk Search

Index Data Retrieve

aquillius
New Member

I deleted data on my index using code "index = asr_local | delete "

but when I added new data on my database, i can't retrieve it on my index. when i search index = asr_local, no results found..

What seems to be the problem and how can i retrieve again data?

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi aquilius,

the delete command does not delete data from the index, the events will just no longer show as results but are still in the index. Also Splunk still knows what was indexed and therefor does not re-index the same data again .... unless you do some work.

The radical method is to clean the fishbucket index. That will remove the memory of every files, be warned it will re-index all data.

  • on an indexer splunk clean eventdata -index _fishbucket
  • on a forwarder by removing the folder $SPLUNK_HOME/var/lib/splunk/fishbucket

You could selectively forgot a single file from the fish bucket like this:

splunk cmd btprobe -d $SPLUNK_HOME/var/lib/splunk/fishbucket/splunk_private_db --file $FILE --reset

You could manually re-index each file with the oneshot option

splunk add oneshot "/path/to/my/file.log" -sourcetype mysourcetype

You could modify the first line of the files to re-index, by default Splunk checks the first 256 chars of a file to differentiate them. If you had a simple comment on the first line it wil reindex it

You could change the crcSalt, create a new input for a new folder, add all the correct sourcetypes, etc... add the option crcSalt=<SOURCE> then move or copy the files to be re-index to the folder.

hope this helps ...

cheers, MuS

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...