If you have a 3 node index cluster in prod and you create a report that ends with the delete
option and schedule the job to run on the last day, it will definitely delete
all copies of the data and it will not appear in any search results after that.
Below link from the Splunk document describes various ways a data for index can be removed.
The best one is "clean" command from Splunk CLI as it can be automated. Note that it doesn't work in clustered environment.
For scheduling to last day of month, there is no direct cron available in SPlunk to do that but you can run a search daily, check if the current date is last day of month, if yes then as an alert action run your script for cleanup indexed data.
We have a 3 node index cluster in prod and this will eventually be moved to prod.
by creating a report with delete option and scheduling the job to run on the last day, will that work in a cluster?