Clean/Reset all indexes on Splunk

Posted in Splunk on February 9th, 2011 by phoenixdigital

./splunk help clean

To permanently remove event data from all indexes, type:

./splunk stop
./splunk clean eventdata

To permanently remove event data from a single index, type:

./splunk stop
./splunk clean eventdata -index <index_name>

Add the -f parameter to force clean to skip its confirmation prompts.

Ref: http://www.splunk.com/base/Documentation/latest/Admin/RemovedatafromSplunk

To force a reload of all conf files perform a search like
| extract reload=true

To reload XML dashboards click on the Splunk logo on the top left of the page

To reload the navigation XML
http://YOUR_SERVER:8000/en-US/debug/refresh?entity=/data/ui/nav

To reload views
http://YOUR_SERVER:8000/en-US/debug/refresh?entity=/data/ui/views

To see the source of a dashboard add the following to the end of a URL
?showsource=true
you may need to only do this if a ? is already present in the URL
&showsource=true

Tags: , , ,