<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Index  archiving not effective in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709180#M21344</link>
    <description>&lt;P&gt;Hello, may I ask two questions&lt;BR /&gt;1) We are currently experiencing a 200 day archive configuration for the index, but it has not taken effect. Could you please advise on the triggering conditions for the frozenTimePeriodInsecs parameter.&lt;BR /&gt;2) Which is higher in priority between the frozenTimePeriodInsecs parameter of the index and maxTotalDataSizeMB?&lt;/P&gt;</description>
    <pubDate>Mon, 20 Jan 2025 02:45:50 GMT</pubDate>
    <dc:creator>jiaminyun</dc:creator>
    <dc:date>2025-01-20T02:45:50Z</dc:date>
    <item>
      <title>Splunk Index  archiving not effective</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709180#M21344</link>
      <description>&lt;P&gt;Hello, may I ask two questions&lt;BR /&gt;1) We are currently experiencing a 200 day archive configuration for the index, but it has not taken effect. Could you please advise on the triggering conditions for the frozenTimePeriodInsecs parameter.&lt;BR /&gt;2) Which is higher in priority between the frozenTimePeriodInsecs parameter of the index and maxTotalDataSizeMB?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 02:45:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709180#M21344</guid>
      <dc:creator>jiaminyun</dc:creator>
      <dc:date>2025-01-20T02:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Index  archiving not effective</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709187#M21348</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231680"&gt;@jiaminyun&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;The priority between frozenTimePeriodInSecs and maxTotalDataSizeMB can be understood as follows:&lt;/P&gt;&lt;P class=""&gt;maxTotalDataSizeMB&lt;STRONG&gt; Takes Precedence&lt;/STRONG&gt;: If the index size exceeds&lt;/P&gt;&lt;P class=""&gt;maxTotalDataSizeMB before reaching the time set in frozenTimePeriodInSecs, the data will be rolled to frozen state based on the size limit.&lt;/P&gt;&lt;P class=""&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setaretirementandarchivingpolicy" target="_blank" rel="noopener"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setaretirementandarchivingpolicy&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 05:15:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709187#M21348</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-01-20T05:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Index  archiving not effective</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709188#M21349</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231680"&gt;@jiaminyun&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk prioritizes evaluating the total data size in the index against the `maxTotalDataSizeMB` parameter. If the total size exceeds the defined limit, Splunk will begin deleting the oldest buckets, regardless of whether they satisfy the retention period defined by `frozenTimePeriodInSecs`. Conversely, if the data size remains within the specified limit, the system will then assess buckets based on the `frozenTimePeriodInSecs` parameter to archive or delete those exceeding the time threshold. To ensure consistent data retention for a specific duration (e.g., 200 days), it is essential to configure `maxTotalDataSizeMB` to accommodate the anticipated volume of data for the desired retention period.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 05:17:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709188#M21349</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-01-20T05:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Index  archiving not effective</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709189#M21350</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231680"&gt;@jiaminyun&lt;/a&gt;&lt;/P&gt;&lt;P&gt;If you find this solution satisfactory, please proceed to accept it.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 05:36:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709189#M21350</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-01-20T05:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Index  archiving not effective</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709190#M21351</link>
      <description>&lt;P&gt;Your help was very much appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 05:40:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709190#M21351</guid>
      <dc:creator>jiaminyun</dc:creator>
      <dc:date>2025-01-20T05:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Index  archiving not effective</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709203#M21356</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;here is couple of links to old answers where we are discussed this.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Deployment-Architecture/Right-number-and-size-of-hot-warm-cold-buckets/m-p/681358" target="_blank"&gt;https://community.splunk.com/t5/Deployment-Architecture/Right-number-and-size-of-hot-warm-cold-buckets/m-p/681358&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Deployment-Architecture/Hot-Warm-Cold-bucket-sizing-How-do-I-set-up-my-index-conf-with/m-p/634696" target="_blank"&gt;https://community.splunk.com/t5/Deployment-Architecture/Hot-Warm-Cold-bucket-sizing-How-do-I-set-up-my-index-conf-with/m-p/634696&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Deployment-Architecture/Index-rolling-off-data-before-retention-age/m-p/684799" target="_blank"&gt;https://community.splunk.com/t5/Deployment-Architecture/Index-rolling-off-data-before-retention-age/m-p/684799&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Enterprise/Why-do-we-have-warm-buckets/m-p/700835" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Enterprise/Why-do-we-have-warm-buckets/m-p/700835&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Some of those are little bit out of direct scope of your question, but still those give to you better understanding how this is working.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 07:49:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709203#M21356</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-20T07:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Index  archiving not effective</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709208#M21358</link>
      <description>You must also remember that all time based activities has calculated on newest event in bucket. This is usually the reason why you have lot of of old events which should be archived by time. More about this on those links which I add on another post.</description>
      <pubDate>Mon, 20 Jan 2025 08:28:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709208#M21358</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-20T08:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Index  archiving not effective</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709210#M21360</link>
      <description>Not exactly that way. You must remember that all time based calculations has done by newest event on bucket! And you could have events e.g. within several months or even longer period (e.g. there is some reindexing for old data) in one bucket. See more from those links which I posted.</description>
      <pubDate>Mon, 20 Jan 2025 08:31:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709210#M21360</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-20T08:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Index  archiving not effective</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709213#M21361</link>
      <description>&lt;P&gt;谢谢。目前，假设我设置总索引大小为 500GB，实际使用了 140GB，配置的存档周期为 200 天，Hot/Arm/Guild Bucket 的最大大小设置为 auto-highvolume GB，但数据已经保留 4 年，仍然没有存档&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2025 08:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Index-archiving-not-effective/m-p/709213#M21361</guid>
      <dc:creator>jiaminyun</dc:creator>
      <dc:date>2025-01-20T08:44:28Z</dc:date>
    </item>
  </channel>
</rss>

