diff --git a/docs/manage/deletion-requests.md b/docs/manage/deletion-requests.md index 2b16eccba6..3c08c548bd 100644 --- a/docs/manage/deletion-requests.md +++ b/docs/manage/deletion-requests.md @@ -53,26 +53,27 @@ Data cannot be recovered once it gets deleted. Ensure that you have appropriatel ### From a Log Search -#### Delete audit events - -The Audit Event Index has detailed JSON logs. To search for audit events for data deletion logs, use metadata field `_sourceCategory=deletionRule`. For example, to search for data deletion logs you would use the query: - -``` -(_index=sumologic_audit_events) AND _sourceCategory=deletionRule -``` - -#### Delete system events +1. In the **Log Search**, search for the required logs that needs to be deleted. +1. Click the cog icon, then in the dropdown, select **Create Deletion Request**.
deletion request +1. In the popup window, enter a **Name** and **Reason** for your data deletion request, then click **Create Request**. + +#### Delete events -The System Event Index has detailed JSON logs. To search for system events for data deletion logs, use metadata field `_sourceCategory=deletionRule`. For example, to search for data deletion logs you would use the query: +The Audit Event Index and System Event Index has detailed JSON logs. To search for audit events or system events for data deletion logs, use metadata field `_sourceCategory=deletionRule`. -``` -(_index=sumologic_system_events) AND _sourceCategory=deletionRule +```sql +(_index=sumologic_*_events) AND _sourceCategory=deletionRule +| json field=_raw "resourceIdentity.name" as name nodrop +| json field=_raw "resourceIdentity.id" as id nodrop +| json field=_raw "eventName" +| json field=_raw "operator.interface" as operator nodrop +| json field=_raw "operator.email" as email nodrop +| count by _messagetime,eventname,name,id,operator,email,_view +| sort _messagetime asc ``` -1. In the **Log Search**, search for the required logs that needs to be deleted. -1. Click the cog icon, then in the dropdown, select **Create Deletion Request**.
deletion request -1. In the popup window, enter a **Name** and **Reason** for your data deletion request, then click **Create Request**. +The events `DeletionRuleCreated` and `DeletionRuleStateUpdated` are contained in the `sumologic_audit_events` index and `DeletionRuleProcessingConcluded` is in the `sumologic_system_events` index. ## Cancel a deletion request @@ -100,4 +101,4 @@ Each deletion request is limited to 100,000 messages. This means that any deleti ### Supported operators -Currently, we only support [`as`](/docs/search/search-query-language/search-operators/as), [`concat`](/docs/search/search-query-language/search-operators/concat), [`contains`](/docs/search/search-query-language/search-operators/contains), [`decToHex`](/docs/search/search-query-language/search-operators/dectohex), [`floor`](/docs/search/search-query-language/math-expressions/floor), [`if`](/docs/search/search-query-language/search-operators/if), [`in`](/docs/search/search-query-language/search-operators/in), [`lookup`](/docs/search/search-query-language/search-operators/lookup), [`toLower`](/docs/search/search-query-language/search-operators/tolowercase-touppercase), [`matches`](/docs/search/search-query-language/search-operators/matches), [`parse`](/docs/search/search-query-language/parse-operators), [`toUpper`](/docs/search/search-query-language/search-operators/tolowercase-touppercase), and [`where`](/docs/search/search-query-language/search-operators/where) search query operators. \ No newline at end of file +Currently, we only support [`as`](/docs/search/search-query-language/search-operators/as), [`concat`](/docs/search/search-query-language/search-operators/concat), [`contains`](/docs/search/search-query-language/search-operators/contains), [`decToHex`](/docs/search/search-query-language/search-operators/dectohex), [`floor`](/docs/search/search-query-language/math-expressions/floor), [`if`](/docs/search/search-query-language/search-operators/if), [`in`](/docs/search/search-query-language/search-operators/in), [`lookup`](/docs/search/search-query-language/search-operators/lookup), [`toLower`](/docs/search/search-query-language/search-operators/tolowercase-touppercase), [`matches`](/docs/search/search-query-language/search-operators/matches), [`parse`](/docs/search/search-query-language/parse-operators), [`toUpper`](/docs/search/search-query-language/search-operators/tolowercase-touppercase), and [`where`](/docs/search/search-query-language/search-operators/where) search query operators.