Clean/Reset all indexes on Splunk

Posted in Splunk on February 9th, 2011 by phoenixdigital

./splunk help clean

To permanently remove event data from all indexes, type:

./splunk stop
./splunk clean eventdata

To permanently remove event data from a single index, type:

./splunk stop
./splunk clean eventdata -index <index_name>

Add the -f parameter to force clean to skip its confirmation prompts.


To force a reload of all conf files perform a search like
| extract reload=true

To reload XML dashboards click on the Splunk logo on the top left of the page

To reload the navigation XML

To reload views

To see the source of a dashboard add the following to the end of a URL
you may need to only do this if a ? is already present in the URL

