<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexers cleaning in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexers-cleaning-How-is-it-performed-in-clustered-architecture/m-p/617792#M14273</link>
    <description>&lt;P&gt;"Cleaning" old events from indexes have done by setting size of index (maxTotalDataSizeMB) and/or max lifetime for events (frozenTimePeriodInSecs). There are some other attributes which can fine tune the time and indexes sizes. See those from&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf#PER_INDEX_OPTIONS" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf#PER_INDEX_OPTIONS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Here is old conf presentation about Data Lifecycle&amp;nbsp;&lt;A href="https://conf.splunk.com/files/2017/slides/splunk-data-life-cycle-determining-when-and-where-to-roll-data.pdf" target="_blank"&gt;https://conf.splunk.com/files/2017/slides/splunk-data-life-cycle-determining-when-and-where-to-roll-data.pdf&lt;/A&gt;. It's still valid, but it don't cover Splunk SmartStore usage which have some other parameters to restrict lifecycle.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Thu, 20 Oct 2022 06:18:23 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-10-20T06:18:23Z</dc:date>
    <item>
      <title>Indexers cleaning- How is it performed in clustered architecture?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexers-cleaning-How-is-it-performed-in-clustered-architecture/m-p/617653#M14258</link>
      <description>&lt;P&gt;Hello, everyone!&lt;/P&gt;
&lt;P&gt;I have few questions about indexers cleaning:&lt;/P&gt;
&lt;P&gt;- How it's performed in clustered architecture?&lt;/P&gt;
&lt;P&gt;- Does it really needed? Do I correctly understand that frozen buckets delete automatically?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 14:10:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexers-cleaning-How-is-it-performed-in-clustered-architecture/m-p/617653#M14258</guid>
      <dc:creator>bosseres</dc:creator>
      <dc:date>2022-10-19T14:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers cleaning</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexers-cleaning-How-is-it-performed-in-clustered-architecture/m-p/617692#M14263</link>
      <description>&lt;P&gt;What do you mean by "indexers cleaning"?&amp;nbsp; What do you expect to happen during this process?&lt;/P&gt;&lt;P&gt;Yes, you understand correctly.&amp;nbsp; By default, frozen buckets are deleted automatically.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 12:48:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexers-cleaning-How-is-it-performed-in-clustered-architecture/m-p/617692#M14263</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-10-19T12:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers cleaning</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexers-cleaning-How-is-it-performed-in-clustered-architecture/m-p/617790#M14272</link>
      <description>&lt;P&gt;I mean cleaning indexers from old logs&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 06:05:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexers-cleaning-How-is-it-performed-in-clustered-architecture/m-p/617790#M14272</guid>
      <dc:creator>bosseres</dc:creator>
      <dc:date>2022-10-20T06:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: Indexers cleaning</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Indexers-cleaning-How-is-it-performed-in-clustered-architecture/m-p/617792#M14273</link>
      <description>&lt;P&gt;"Cleaning" old events from indexes have done by setting size of index (maxTotalDataSizeMB) and/or max lifetime for events (frozenTimePeriodInSecs). There are some other attributes which can fine tune the time and indexes sizes. See those from&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf#PER_INDEX_OPTIONS" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf#PER_INDEX_OPTIONS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Here is old conf presentation about Data Lifecycle&amp;nbsp;&lt;A href="https://conf.splunk.com/files/2017/slides/splunk-data-life-cycle-determining-when-and-where-to-roll-data.pdf" target="_blank"&gt;https://conf.splunk.com/files/2017/slides/splunk-data-life-cycle-determining-when-and-where-to-roll-data.pdf&lt;/A&gt;. It's still valid, but it don't cover Splunk SmartStore usage which have some other parameters to restrict lifecycle.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 06:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Indexers-cleaning-How-is-it-performed-in-clustered-architecture/m-p/617792#M14273</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-10-20T06:18:23Z</dc:date>
    </item>
  </channel>
</rss>

