Is it safe to clear the _internal index like this? Or should this never be done in the first place? What are the issues that could arise from doing this?
$SPLUNK_HOME/bin/splunk clean eventdata -index _internal
Yes, it's safe to do. Other than not having the internal logs anymore, it doesn't cause any harm.
Yes, it's safe to do. Other than not having the internal logs anymore, it doesn't cause any harm.
I did this, so what do I need to do if I want it enabled again ? I see the directory for _internal growing but search just isn't seeing it anymore.