Skip to content
Discussion options

You must be logged in to vote

Rather than doing it from the command line, probably the safest way to do this would be to:

  1. Stop Malcolm
  2. Go into Kibana on your Elasticsearch cluster
  3. Go into Kibana's index management UI (I'm not much of a Kibana user, I assume it has this?)
  4. Delete all of the indexes that begin with arkime
  5. Start Malcolm back up

Otherwise, use the elasticsearch DELETE api to delete the arkime* indices.

Replies: 8 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by mmguero
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
elastic Related to issue with external ElasticSearch/Kibana output
2 participants
Converted from issue

This discussion was converted from issue #669 on May 15, 2025 12:59.