Submitted by wtanaka on Fri, 2011-08-19 05:42 (
To remove all of the data from a specific Splunk index without using the slow
"| delete" command:
- Stop Splunk
- Delete all the data from a specific index (for example "
/path/to/splunk clean eventdata -index main