Getting Data In

How to remove the Splunk Search Tutorial data that I uploaded earlier?

vivekkannansiva
New Member

I had imported the tutorial data for learning purposes, but I don't need that data anymore. How do I delete this data from my Splunk instance?

0 Karma

ChrisG
Splunk Employee
Splunk Employee

There is a topic, Remove indexes and indexed data, in the Managing Indexers and Clusters of Indexers manual. You can use the deletecommand to handle this, if you have the data in a main index, or you can use the clean command if you have it in a separate index and want to remove that index entirely. Proceed with caution, though, and read the docs carefully so you understand what is actually happening and not happening with these commands.

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...