Splunk Search

Why is it called delete when it doesn't delete, but hide data?

sbarnes88
New Member

I find this very ridiculous considering that the terminology used is not accurate in what it is doing. When doing a search to hide data from being searchable, it calls it delete. Well it's not deleting the data from the logs so its essentially a misnomer calling the function delete. Instead either call it hide or removeFromSearch - some other name that gives it meaning.

I've spent the last 2 hours searching how to reclaim disk space without removing the primary index - its not possible and people have been requesting this kind of utility for years! Naming conventions mean a lot. They carry a lot of meaning and seeing this kind of misnomer is really frustrating.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...