Knowledge Management

Is it safe to clear event data from _internal?

rayfoo
Path Finder

Is it safe to clear the _internal index like this? Or should this never be done in the first place? What are the issues that could arise from doing this?

$SPLUNK_HOME/bin/splunk clean eventdata -index _internal

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Yes, it's safe to do. Other than not having the internal logs anymore, it doesn't cause any harm.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Yes, it's safe to do. Other than not having the internal logs anymore, it doesn't cause any harm.

rsia23
Explorer

I did this, so what do I need to do if I want it enabled again ? I see the directory for _internal growing but search just isn't seeing it anymore.

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...