Getting Data In

Delete/clean all the contents of splunk

harshavrath
Contributor

Hi.

How to delete/clear all the indexed events,saved searches.How to make it brand new as it was after installing for the first time.

Any Suggestions are Appreciated,

Cheers.

0 Karma
1 Solution

chimbudp
Contributor

1) The below command will not delete the indexed data from the Splunk , instead it doesn't show the results in splunk search.
index=* | delete

2) Below is the purge script - copt it to your splunk server and save as (script.sh). Specify your app names if you would like to delete your local configurations.

Execute with command : sh purge.sh

This will cleanup all the indexed data and your app local configurations

#!/bin/bash
clear
/opt/splunk/bin/splunk stop
/opt/splunk/bin/splunk clean eventdata
rm -rf /opt/splunk/etc/apps/Your_app_name1/local/*
rm -rf /opt/splunk/etc/apps/your_app_name2/local/*
/opt/splunk/bin/splunk start

View solution in original post

chimbudp
Contributor

1) The below command will not delete the indexed data from the Splunk , instead it doesn't show the results in splunk search.
index=* | delete

2) Below is the purge script - copt it to your splunk server and save as (script.sh). Specify your app names if you would like to delete your local configurations.

Execute with command : sh purge.sh

This will cleanup all the indexed data and your app local configurations

#!/bin/bash
clear
/opt/splunk/bin/splunk stop
/opt/splunk/bin/splunk clean eventdata
rm -rf /opt/splunk/etc/apps/Your_app_name1/local/*
rm -rf /opt/splunk/etc/apps/your_app_name2/local/*
/opt/splunk/bin/splunk start

harshavrath
Contributor

Thank you.I just stopped splunk & deleted the folder.

0 Karma

linu1988
Champion

stop splunk

cd splunk\bin\
splunk clean eventdata -index <index_name>

easiest way, stop splunk. Delete the index store folders. restart splunk

0 Karma

harshavrath
Contributor

Hi i have installed Splunk on windows, how to delete the indexed data.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...