Is there any way of deleting data from a specific source (for example a file) that has already been indexed by Splunk? Maybe to reindex data from the same source but which this time is different from the previous data.
Forums: SplunkAdministration: Deleting data from a specific source?
Previous Topic: Unusual Hosts showing in Splunk -- Where do these come from? | Next Topic: Is splunk safe in production
Posts 1–3 of 3
| Post to this topic
The delete command will not 'remove' data from a specific source, but it will hide it from search:
thanks for that
Post to this topic
You must be logged in to post a reply.