Hi,
By mistake i ran the splunk clean command eventdata is deleted from database.
.Command i ran : /splunk clean eventdata -index main -f
Cleaning database main.
How to add again can someone please help me.
Thanks,
Hi Manekar,
clean eventdata command will remove data permanently from index, but not index definition. You have to re-index that data in same index.