<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data age in splunk in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/700667#M20376</link>
    <description>&lt;P&gt;Your license measures breaks down by index for daily usage.&amp;nbsp; Just check the DMC for the reports.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Oct 2024 13:57:14 GMT</pubDate>
    <dc:creator>dural_yyz</dc:creator>
    <dc:date>2024-10-01T13:57:14Z</dc:date>
    <item>
      <title>Why is the age of the data larger than the frozenTimePeriodInSecs time without being deleted?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/507736#M2457</link>
      <description>&lt;P&gt;Hi Splunk Team&lt;/P&gt;
&lt;P&gt;Why is the age of the data larger than the frozenTimePeriodInSecs time without being deleted&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vumanhtai_0-1594096169238.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9512i93B1F2F656B1FD6E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vumanhtai_0-1594096169238.png" alt="vumanhtai_0-1594096169238.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;My config index is as follows&lt;/P&gt;
&lt;P&gt;frozenTimePeriodInSecs = 38880000&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 15:06:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/507736#M2457</guid>
      <dc:creator>vumanhtai</dc:creator>
      <dc:date>2023-02-28T15:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Data age in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/508937#M2600</link>
      <description>&lt;P&gt;Buckets are rolled to frozen when all events have at least&amp;nbsp;&lt;SPAN&gt;frozenTimePeriodInSecs old. When there are some “newer” and “older” events on the same individual bucket it has rolled to frozen when the newest event has enough old.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 22:30:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/508937#M2600</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-13T22:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: Data age in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/548473#M5626</link>
      <description>&lt;P&gt;Does this mean that eventually the bucket will move to frozen when the "newest" event is more than the the frozentimeperiodinsec setting?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is there a way to prevent this behavior so that all indexes have the data age of the frozentimeperiodinsecs setting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 17:54:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/548473#M5626</guid>
      <dc:creator>jordanking1992</dc:creator>
      <dc:date>2021-04-19T17:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Data age in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/548538#M5628</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;It works just like that. When the newest event has enough old then the whole bucket will be moved to frozen.&lt;/P&gt;&lt;P&gt;At least I don't know that kind of feature. When you are thinking how those events are stored into buckets, you probably understand how hard and impossible that kind of process will be. Of course you could try to avoid it with planning of your indexes e.g. what data to which index etc. and ensure that you haven't any older data (e.g. start collect some new hosts, which contains old data) on same indexes.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 20 Apr 2021 05:56:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/548538#M5628</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-04-20T05:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: Data age in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/548676#M5632</link>
      <description>&lt;P&gt;My concern is that if enough indexes are storing the data longer than the expected retention, do we rely on maxVolumeSize to start deleting events if the disk starts to fill up?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Apr 2021 20:02:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/548676#M5632</guid>
      <dc:creator>jordanking1992</dc:creator>
      <dc:date>2021-04-20T20:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: Data age in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/632602#M15526</link>
      <description>&lt;P&gt;I know this is an old topic, but it took me long time to understand it, so I guess it's worth helping a little &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;There's no direct approach; however if you do some digging you can come to an acceptable solution:&lt;/P&gt;&lt;P&gt;I also found that my indexes were keeping data above the FrozenTimePeriodInSecs; that's because, if the ingestion rate is not very high, some buckets can contain data belonging to more than one day of ingestion, and therefore those &lt;STRONG&gt;buckets won't be frozen until the most recent event reaches the FrozenTimePeriodInSecs&lt;/STRONG&gt; limit. If one bucket has, say a whole month's data, by the time it's frozen it will be exceeding the FrozenTimePeriodInSecs by a month.&lt;/P&gt;&lt;P&gt;What I did was study the average amount of data ingested by each index (in my case, around 0.5GB) and configure&amp;nbsp;&lt;SPAN&gt;maxDataSize to this value; this way each hot bucket will be at most&amp;nbsp;0.5GB, and it will contain data from just one day.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You'll find that Splunk criteria for bucket creation is not obvious; sometimes it creates, for the same date, a 45MB bucket and another one of 123MB (it's just an example) and I don't understand why, but the important thing is that t&lt;/SPAN&gt;&lt;SPAN&gt;his makes the rotation much more "agile", since buckets are inmediately deleted when they reach the FrozenTimePeriodInSecs limit.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 14:34:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/632602#M15526</guid>
      <dc:creator>MiniNenya</dc:creator>
      <dc:date>2023-02-28T14:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Data age in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/632606#M15527</link>
      <description>&lt;P&gt;I forgot to mention that, alternatively, you can configure your hot buckets to roll to warm based solely on their age with the parameter maxHotSpanSecs.&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 14:58:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/632606#M15527</guid>
      <dc:creator>MiniNenya</dc:creator>
      <dc:date>2023-02-28T14:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Data age in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/700651#M20375</link>
      <description>&lt;P&gt;Dear MiniNenya,&lt;/P&gt;&lt;P&gt;According to your explain, how did you calculate &lt;STRONG&gt;"average amount of data ingested by each index"&amp;nbsp;&lt;/STRONG&gt;?&lt;BR /&gt;&lt;BR /&gt;Sincerely,&lt;BR /&gt;Benny On&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 01 Oct 2024 10:42:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/700651#M20375</guid>
      <dc:creator>thanh_on</dc:creator>
      <dc:date>2024-10-01T10:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: Data age in splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/700667#M20376</link>
      <description>&lt;P&gt;Your license measures breaks down by index for daily usage.&amp;nbsp; Just check the DMC for the reports.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 13:57:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-is-the-age-of-the-data-larger-than-the/m-p/700667#M20376</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-10-01T13:57:14Z</dc:date>
    </item>
  </channel>
</rss>

