-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating
Mastering Splunk
By :
While Splunk continues to write data (events) to its indexes, you can remove specified indexed data or even an entire index from your Splunk environment. So, let's have a look at how to do this.
Splunk affords the delete special operator to delete events from your Splunk searches. The Splunk delete operator flags all the events returned so that future searches don't return them. This data will not be visible to any user (even admin permission users) when searching. However, just flagging this data using delete does not free up the disk space, as data is not removed from the index; it is just invisible to searches.
In Chapter 2, Advanced Searching, we discussed the Splunk search pipeline and various operators. The delete operator is an extraordinary operator that can only be run by a user granted the delete_by_keyword capability. Even the Splunk admin user does not have this capability granted; you must explicitly grant it to users...
Change the font size
Change margin width
Change background colour