<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk buckets default retention period in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654850#M17157</link>
    <description>&lt;P&gt;Perhaps there is an error in the bucket searches.&amp;nbsp; You may be able to find and correct it by clicking on the "Open in search" icon (magnifying glass).&lt;/P&gt;</description>
    <pubDate>Fri, 18 Aug 2023 12:24:03 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-08-18T12:24:03Z</dc:date>
    <item>
      <title>What is Splunk buckets default retention period?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654703#M17148</link>
      <description>&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Hi Team,&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;I wanted to know what the default retention period of buckets in Splunk i.e. (HOT, WARM, COLD, FROZEN, THAWED).&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;How can I know the retention period of each bucket and where can check the retention period of each bucket?&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;please could you help me with the location or path of each bucket's configurations in Splunk. Actually, I'm new to these bucket concepts. we have only 2 indexers ,1 license master and 1 search head.&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Praseeda.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 17:49:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654703#M17148</guid>
      <dc:creator>prasireddy</dc:creator>
      <dc:date>2023-08-18T17:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk buckets default retention period</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654733#M17150</link>
      <description>&lt;P&gt;Data retention is set on a per-index basis rather than per-bucket.&amp;nbsp; Retention settings apply only to hot, warm, and cold buckets.&amp;nbsp; Splunk does not manage frozen or thawed buckets.&lt;/P&gt;&lt;P&gt;You can find the default retention settings in $SPLUNK_HOME/etc/system/default/indexes.conf, but those settings can be overridden by another indexes.conf file.&amp;nbsp; Use btool to see the current (on-disk) config:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool indexes list&lt;/LI-CODE&gt;&lt;P&gt;There's a good .conf presentation on the topic at &lt;A href="https://www.google.com/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=&amp;amp;ved=2ahUKEwj3_s6al-SAAxVxgIQIHZB8C_4QFnoECCUQAQ&amp;amp;url=https%3A%2F%2Fconf.splunk.com%2Ffiles%2F2017%2Fslides%2Fsplunk-data-life-cycle-determining-when-and-where-to-roll-data.pdf&amp;amp;usg=AOvVaw2gaVE-_QJwICaCZc0RNQ0Z&amp;amp;opi=89978449" target="_blank"&gt;https://www.google.com/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=&amp;amp;ved=2ahUKEwj3_s6al-SAAxVxgIQIHZB8C_4QFnoECCUQAQ&amp;amp;url=https%3A%2F%2Fconf.splunk.com%2Ffiles%2F2017%2Fslides%2Fsplunk-data-life-cycle-determining-when-and-where-to-roll-data.pdf&amp;amp;usg=AOvVaw2gaVE-_QJwICaCZc0RNQ0Z&amp;amp;opi=89978449&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 17:14:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654733#M17150</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-08-17T17:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk buckets default retention period</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654843#M17156</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&lt;FONT color="#0070f3"&gt;&lt;U&gt;richgalloway,&lt;/U&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually, when I check in Setting--&amp;gt;Monitoring console---&amp;gt;Indexing---&amp;gt;Indexes and volumes----&amp;gt;Index Details: Instance but here in buckets I didn't see anything for the same I'm attaching screen shot.&amp;nbsp;&lt;BR /&gt;Please could you explain once? ￼&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="buckets.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26869i1772A851E47891D9/image-size/large?v=v2&amp;amp;px=999" role="button" title="buckets.png" alt="buckets.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MicrosoftTeams-image (7).png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26870i833C81729CC08B79/image-size/large?v=v2&amp;amp;px=999" role="button" title="MicrosoftTeams-image (7).png" alt="MicrosoftTeams-image (7).png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MicrosoftTeams-image (9).png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26871iB767110BFBE2F779/image-size/large?v=v2&amp;amp;px=999" role="button" title="MicrosoftTeams-image (9).png" alt="MicrosoftTeams-image (9).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 11:24:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654843#M17156</guid>
      <dc:creator>prasireddy</dc:creator>
      <dc:date>2023-08-18T11:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk buckets default retention period</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654850#M17157</link>
      <description>&lt;P&gt;Perhaps there is an error in the bucket searches.&amp;nbsp; You may be able to find and correct it by clicking on the "Open in search" icon (magnifying glass).&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 12:24:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654850#M17157</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-08-18T12:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk buckets default retention period</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654854#M17158</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Please could explain this paths, retention policies and bucket configurations from the screen shot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Praseeda&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 12:46:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654854#M17158</guid>
      <dc:creator>prasireddy</dc:creator>
      <dc:date>2023-08-18T12:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk buckets default retention period</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654856#M17159</link>
      <description>&lt;P&gt;If you have access to REST you could try to something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest splunk_server=local /services/data/indexes
| join title
    [| rest splunk_server=local /services/data/indexes-extended]
| fields title *ath* *MB *ize* max*
| fields - *expand*&lt;/LI-CODE&gt;&lt;P&gt;If/when you have distributed (clustered) environment you need to handle same records from all search peers (especially indexes-extended). You see those when change splunk_server=&amp;lt;your indexers&amp;gt;.&amp;nbsp; Just some stats etc. and you will get those values. Also you must check those fields which which I had added there that those are what you are needing.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 12:53:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654856#M17159</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-08-18T12:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk buckets default retention period</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654868#M17162</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Thank you. I will check.&amp;nbsp;&lt;BR /&gt;Moreover, it not a clustered Env we have only 2 indexers,1 license master and 1 search head.&amp;nbsp;&lt;BR /&gt;And I have attached the&amp;nbsp;&lt;SPAN&gt;file, please&amp;nbsp;could explain this paths, retention policies and bucket configurations from the screen&amp;nbsp;&lt;/SPAN&gt;shot.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks, in advance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 13:36:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654868#M17162</guid>
      <dc:creator>prasireddy</dc:creator>
      <dc:date>2023-08-18T13:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk buckets default retention period</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654871#M17163</link>
      <description>&lt;P&gt;You should read&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;pointed .conf presentation. There are lot of other presentations too, which you could found from .conf site.&lt;/P&gt;&lt;P&gt;You should also read the base information&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.0/Indexer/Aboutmanagingindexes" target="_self"&gt;About managing indexes&lt;/A&gt;&amp;nbsp;from docs. Probably there are more on lantern? Also there are many answers already which you should check if above documentation isn't enough.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 13:43:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/What-is-Splunk-buckets-default-retention-period/m-p/654871#M17163</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-08-18T13:43:46Z</dc:date>
    </item>
  </channel>
</rss>

