Hello Splunkers,
Lately I had to delete specific source type logs from the index and used the command |delete from the search head.
However when i navigate to the buckets and zcat the journal.gz from the raw data and write it to another file I could read the file.
Is there any way that I could remove the specific sourcetype data from the disk itself.
Index cleaning is not an option for me as I have important logs residing in the same index.
Regards,
Ankith
Hi ankithnageshshetty,
long answer short: no. Not by using any available Splunk commands.
And btw, the delete
command only makes events as not searchable, but does not delete any events - see the docs http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Delete#Description
cheers, MuS