<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk shows only 9 months (270 days) data in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/624953#M14867</link>
    <description>&lt;P&gt;&lt;SPAN&gt;I did, the size defined is 500GB and most of the indexes are around 300-400GB.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Dec 2022 10:46:21 GMT</pubDate>
    <dc:creator>spodda01da</dc:creator>
    <dc:date>2022-12-21T10:46:21Z</dc:date>
    <item>
      <title>Splunk shows only 9 months (270 days) data- How do I increase the retention period?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/624944#M14863</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;I got a strange issue and unable to find a fix.&lt;/P&gt;
&lt;P&gt;All the indexes have a longer retention period but the oldest data is limited to 270 days. I checked the index cluster but did not find anything which could be causing this issue. Here is the configuration for all indexes:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;[example1]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;coldPath = volume:primary/example1/colddb&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;homePath = volume:primary/example1/db&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;maxTotalDataSizeMB = 512000&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;thawedPath = $SPLUNK_DB/example1/thaweddb&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;frozenTimePeriodInSecs=39420043&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Checked the index &amp;amp;&amp;nbsp; Indexers disk space and they are still space left for more data.&lt;/P&gt;
&lt;P&gt;Please let me know if anyone have similar experience or suggestion to increase the retention period.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 14:48:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/624944#M14863</guid>
      <dc:creator>spodda01da</dc:creator>
      <dc:date>2022-12-21T14:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk shows only 9 months (270 days) data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/624949#M14864</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/159631"&gt;@spodda01da&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Did you check that your indexe size does not exceed your maxTotalDataSizeMB value (here 512000 MB) ?&lt;/P&gt;&lt;P&gt;Based on the doc :&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.2/admin/Indexesconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.2/admin/Indexesconf&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;* CAUTION: The 'maxTotalDataSizeMB' size limit can be reached before the time 
  limit defined in 'frozenTimePeriodInSecs'&lt;/PRE&gt;&lt;PRE&gt;maxTotalDataSizeMB = &amp;lt;nonnegative integer&amp;gt;
* The maximum size of an index, in megabytes&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;To check the size of your index you can use :&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;du -sch /opt/splunk/var/lib/splunk/&amp;lt;index_name&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 10:37:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/624949#M14864</guid>
      <dc:creator>GaetanVP</dc:creator>
      <dc:date>2022-12-21T10:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk shows only 9 months (270 days) data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/624953#M14867</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I did, the size defined is 500GB and most of the indexes are around 300-400GB.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 10:46:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/624953#M14867</guid>
      <dc:creator>spodda01da</dc:creator>
      <dc:date>2022-12-21T10:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk shows only 9 months (270 days) data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/624963#M14868</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/159631"&gt;@spodda01da&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Run follwing command to check&amp;nbsp;&lt;BR /&gt;if buckets are deleting before&amp;nbsp; actual retion days&lt;BR /&gt;&lt;BR /&gt;index=_internal sourcetype=splunkd bucketmover "*will attempt to freeze*"&lt;BR /&gt;| eval "Index Last Event"=strftime(now,"%d-%m-%y %H:%M:%S")&lt;BR /&gt;| eval "Index First Event"=strftime(latest,"%d-%m-%y %H:%M:%S")&lt;BR /&gt;| eval "Actual Data Stored"=round((now-latest)/86400,0)&lt;BR /&gt;| eval "Index Rention Days"=frozenTimePeriodInSecs/86400&lt;BR /&gt;| table candidate "Index Rention Days" "Actual Data Stored" "Index First Event" "Index Last Event"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SanjayReddy_1-1671623016015.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23105iC6E4F4207C49EA7F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SanjayReddy_1-1671623016015.png" alt="SanjayReddy_1-1671623016015.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if&amp;nbsp; "Actual Data Stored"&amp;nbsp; less than&amp;nbsp;"Index Rention Days" then&amp;nbsp; data ingestion more on index&amp;nbsp;&lt;BR /&gt;and as menioned by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231013"&gt;@GaetanVP&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;maxTotalDataSizeMB&lt;/STRONG&gt; has presencede over &lt;STRONG&gt;frozenTimePeriodInSecs.&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;in that case you may need to increase the disk space&amp;nbsp;&lt;/P&gt;&lt;P&gt;----&lt;BR /&gt;Regards,&lt;BR /&gt;Sanjay Reddy&lt;/P&gt;&lt;P&gt;----&lt;BR /&gt;If this reply helps you, Karma would be appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 11:48:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/624963#M14868</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2022-12-21T11:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk shows only 9 months (270 days) data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/624974#M14869</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236694"&gt;@SanjayReddy&lt;/a&gt;&amp;nbsp;, I ran the script and see following details:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="spodda01da_0-1671627354855.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23108iA81626F22F46B2DD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="spodda01da_0-1671627354855.png" alt="spodda01da_0-1671627354855.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This issue is not specific to one index but with almost all has oldest data of 270 days.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 12:58:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/624974#M14869</guid>
      <dc:creator>spodda01da</dc:creator>
      <dc:date>2022-12-21T12:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk shows only 9 months (270 days) data- How do I increase the retention period?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/625615#M14940</link>
      <description>&lt;P&gt;I still can't find anything which will lead to a solution. Any suggestion will be of great help!&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2023 13:00:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/625615#M14940</guid>
      <dc:creator>spodda01da</dc:creator>
      <dc:date>2023-01-02T13:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk shows only 9 months (270 days) data- How do I increase the retention period?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/625624#M14942</link>
      <description>&lt;P&gt;The data can be frozen (in your case - deleted if not configured otherwise) in one of three cases:&lt;/P&gt;&lt;P&gt;1) The buckets in the index get too old (most recent event in a bucket is older than the retention period for the index) or&lt;/P&gt;&lt;P&gt;2) The index exceeds the size limit&lt;/P&gt;&lt;P&gt;3) The volume hits the size limit.&lt;/P&gt;&lt;P&gt;So you have to verify if any of those three conditions are met.&lt;/P&gt;&lt;P&gt;Additionally, check your effective configuration with btool. Maybe you're looking in a wrong file for the settings.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2023 15:29:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/625624#M14942</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-01-02T15:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk shows only 9 months (270 days) data- How do I increase the retention period?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/656299#M17253</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;Regrettably, the oldest available data across all indexes has been reduced to approximately 7 months.&lt;/P&gt;&lt;P&gt;I have already conducted the following checks:&lt;/P&gt;&lt;P&gt;Current index size: Less than 200GB (configured for 500GB)&lt;BR /&gt;Indexers Disk Size (Cluster): All indexes currently have 30-35% free space.&lt;BR /&gt;frozenTimePeriodInSecs=39420043 (approximately 15 months)&lt;/P&gt;&lt;P&gt;Any assistance with troubleshooting would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 16:22:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/656299#M17253</guid>
      <dc:creator>spodda01da</dc:creator>
      <dc:date>2023-08-31T16:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk shows only 9 months (270 days) data- How do I increase the retention period?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/656303#M17255</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;you could search a reason for deleting bucket from internal index. You can start with&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal *cold* *&amp;lt;your index or bucket Id&amp;gt;* &lt;/LI-CODE&gt;&lt;P&gt;You will get list of buckets. Select one which are frozen. Then use that bucket id to see the process how and why it has frozen.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 17:57:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/656303#M17255</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-08-31T17:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk shows only 9 months (270 days) data- How do I increase the retention period?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/656524#M17282</link>
      <description>&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;I randomly ran it for a few buckets and observed the following message:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Moving bucket='rb_1681312487_1677890027_1731_FBA51F26-2043-4798-B18D-2D637A7347B9', initiating warm_to_cold: from='/Data/splunkdb/o365/db' to='/Data/splunkdb/o365/colddb', caller='chillIfNeeded', reason='maximum number of warm buckets exceeded'.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if this is the reason that could be affecting the data retention period. Initially, I had &lt;EM&gt;&lt;STRONG&gt;"maxHotBuckets = 10"&lt;/STRONG&gt;&lt;/EM&gt; defined, but it's no longer defined, and I've left it as the default value.&lt;/P&gt;&lt;P&gt;[test]&lt;BR /&gt;coldPath = volume:primary/test/colddb&lt;BR /&gt;homePath = volume:primary/test/db&lt;BR /&gt;thawedPath = $SPLUNK_DB/test/thaweddb&lt;BR /&gt;maxTotalDataSizeMB = 512000&lt;BR /&gt;frozenTimePeriodInSecs = 39420043&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2023 04:29:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/656524#M17282</guid>
      <dc:creator>spodda01da</dc:creator>
      <dc:date>2023-09-04T04:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk shows only 9 months (270 days) data- How do I increase the retention period?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/656793#M17302</link>
      <description>&lt;P&gt;To add to the above details, the "thaweddb" folder is blank and doesn't contain any buckets.&lt;/P&gt;&lt;P&gt;For now, I have increased the "frozenTimePeriodInSecs" by a few more months, but I'm not sure if it will work. Any other advice would be very helpful.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 09:18:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/656793#M17302</guid>
      <dc:creator>spodda01da</dc:creator>
      <dc:date>2023-09-06T09:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk shows only 9 months (270 days) data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/754520#M23290</link>
      <description>&lt;P&gt;Dear,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;the issue is resolved for you, for me the same issue with the notable index, we have configured the notable index with 18 mnths retention period and also maxtotaldatasizemb to 20gb, its only used 10 % of 20gb, so as this configuration it need to have data for last 18 months but i can see last 90 days for notable index, when we checked last week its getting from 2nd july when i checked this week its getting from july 12th, so its storing only 90 days,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;can you have any solution for this we are only using hot warm cold not frozen we configured the live data for 18 mnths then it will be deleted, but for notable index its only have for 90 days,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Oct 2025 07:39:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/754520#M23290</guid>
      <dc:creator>Mohammed123</dc:creator>
      <dc:date>2025-10-21T07:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk shows only 9 months (270 days) data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/754549#M23296</link>
      <description>Please create a new question instead of using old one! In that way you will get easier answers for it.</description>
      <pubDate>Tue, 21 Oct 2025 22:45:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/754549#M23296</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-10-21T22:45:57Z</dc:date>
    </item>
  </channel>
</rss>

