<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to copy/forward logs weekly to frozen archive? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-copy-forward-logs-weekly-to-frozen-archive/m-p/586318#M11659</link>
    <description>&lt;P&gt;Thank you for the reply. I guess I'm not asking my question correctly.....&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policy&lt;BR /&gt;1) 90-day - searchable data (HOT/WARM/COLD)&lt;BR /&gt;2) 90-day - frozenTimePeriodInSecs = 7776000 (move data or if 3) is used, delete data)&lt;BR /&gt;3) ?? 7-days - Weekly Powershell script to back-up/copy logs to remote store&lt;/P&gt;&lt;P&gt;My question on for 3) to compensate for some infrastructure issues, I want to back-up the indexed data sooner then waiting for the 2) frozentimeperiodinsecs. This may not be a feasible idea or make logical sense but this is where I'm at, at the moment and trying to think through it.&amp;nbsp; I have setup an index cluster with servers on different network segments to help with single point of failures so I'm hoping I can just depend on the standard 2) frozentimeperiodinsecs policy to move data to frozen remote storage.&lt;BR /&gt;&lt;BR /&gt;Thanks again,&lt;BR /&gt;Sean&lt;/P&gt;</description>
    <pubDate>Wed, 23 Feb 2022 21:20:57 GMT</pubDate>
    <dc:creator>rewritex</dc:creator>
    <dc:date>2022-02-23T21:20:57Z</dc:date>
    <item>
      <title>How to copy/forward logs weekly to frozen archive?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-copy-forward-logs-weekly-to-frozen-archive/m-p/586290#M11656</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm trying to figure out how to do 3 months of HOT/WARM/COLD indexing but copy/forward logs every week to my frozen archive located in a separate location. I'm trying to compensate for some issues we are having with our infrastructure uptime.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Q: Does this make sense and is this possible? Could anyone provide examples or advice?&lt;BR /&gt;Q: Is there a difference is storage space used by sending data in weekly vs monthly(or every 90 days)?&lt;/P&gt;
&lt;P&gt;Also, Splunk is installed into a Windows Environment.&lt;/P&gt;
&lt;P&gt;Thank You,&lt;BR /&gt;Sean&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 18:27:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-copy-forward-logs-weekly-to-frozen-archive/m-p/586290#M11656</guid>
      <dc:creator>rewritex</dc:creator>
      <dc:date>2022-02-23T18:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to copy/forward logs weekly to frozen archive?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-copy-forward-logs-weekly-to-frozen-archive/m-p/586314#M11657</link>
      <description>&lt;P&gt;I'm not entirely sure what you want to do, to be honest.&lt;/P&gt;&lt;P&gt;You want to have your normal hot/warm/cold lifecycle and then once a week move the buckets that have already rolled to frozen somewhere off-site? You can do that of course. After the buckets are rolled to frozen, they are no longer visible to splunk for searching so you can safely move them outside.&lt;/P&gt;&lt;P&gt;But the question is is that really what you want, because that gives you an external copy of _old_ data (the buckets that already "expired).&lt;/P&gt;&lt;P&gt;And in terms of disk usage, the amount of data that gets rolled to frozen over some period should be roughly the same regardless of the schedule. After all it depends on the amount of data ingested.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 20:48:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-copy-forward-logs-weekly-to-frozen-archive/m-p/586314#M11657</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-23T20:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to copy/forward logs weekly to frozen archive?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-copy-forward-logs-weekly-to-frozen-archive/m-p/586318#M11659</link>
      <description>&lt;P&gt;Thank you for the reply. I guess I'm not asking my question correctly.....&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policy&lt;BR /&gt;1) 90-day - searchable data (HOT/WARM/COLD)&lt;BR /&gt;2) 90-day - frozenTimePeriodInSecs = 7776000 (move data or if 3) is used, delete data)&lt;BR /&gt;3) ?? 7-days - Weekly Powershell script to back-up/copy logs to remote store&lt;/P&gt;&lt;P&gt;My question on for 3) to compensate for some infrastructure issues, I want to back-up the indexed data sooner then waiting for the 2) frozentimeperiodinsecs. This may not be a feasible idea or make logical sense but this is where I'm at, at the moment and trying to think through it.&amp;nbsp; I have setup an index cluster with servers on different network segments to help with single point of failures so I'm hoping I can just depend on the standard 2) frozentimeperiodinsecs policy to move data to frozen remote storage.&lt;BR /&gt;&lt;BR /&gt;Thanks again,&lt;BR /&gt;Sean&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 21:20:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-copy-forward-logs-weekly-to-frozen-archive/m-p/586318#M11659</guid>
      <dc:creator>rewritex</dc:creator>
      <dc:date>2022-02-23T21:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to copy/forward logs weekly to frozen archive?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-copy-forward-logs-weekly-to-frozen-archive/m-p/586323#M11660</link>
      <description>&lt;P&gt;OK. So you'd like to copy out warm/cold bucket?&lt;/P&gt;&lt;P&gt;It is possible and copying warm buckets is one of the proposed backup strategies.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/Indexer/Backupindexeddata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.4/Indexer/Backupindexeddata&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But I must say I've never done it myself.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 22:18:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-copy-forward-logs-weekly-to-frozen-archive/m-p/586323#M11660</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-23T22:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to copy/forward logs weekly to frozen archive?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-copy-forward-logs-weekly-to-frozen-archive/m-p/586324#M11661</link>
      <description>&lt;P&gt;Lol, I wasn't searching with the correct words "hot / warm buckets". Thank you for the assistance!&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 22:27:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-copy-forward-logs-weekly-to-frozen-archive/m-p/586324#M11661</guid>
      <dc:creator>rewritex</dc:creator>
      <dc:date>2022-02-23T22:27:05Z</dc:date>
    </item>
  </channel>
</rss>

