Splunk Search

Delete DB Connect indexed data

mavidales
Engager

I'm new to Splunk. Most of our logs are in databases. In testing out DB Connect I added some inputs and removed them later. However, the data that was indexed shows up in searches and I'd like to remove that also. Is there a command to do this? I would use splunk remove index <name> but i don't know the name of the index. There doesn't seem to be a command to remove data by source, or I haven't found it. There is other indexed data that I want to leave in place.

So how do I remove the indexes and data for those specific DB Connect inputs that were removed?

0 Karma
1 Solution

mavidales
Engager

Figured it out.

source="<yoursource>" | delete

Didn't know you could run those kinds of commands in the search bit. That's neat! Yay!

View solution in original post

0 Karma

mavidales
Engager

Figured it out.

source="<yoursource>" | delete

Didn't know you could run those kinds of commands in the search bit. That's neat! Yay!

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Note, this does not clear up space but rather mark those events as deleted.

Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...