<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexes having more data than retention period defined in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405699#M14626</link>
    <description>&lt;P&gt;I pulled data from Search head and found that it has 3 years of data but when i logged in to check configuration files it shows me 1 year retention settings &lt;/P&gt;</description>
    <pubDate>Tue, 15 Jan 2019 17:09:46 GMT</pubDate>
    <dc:creator>ramprakash</dc:creator>
    <dc:date>2019-01-15T17:09:46Z</dc:date>
    <item>
      <title>Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405690#M14617</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;

&lt;P&gt;We have one index defined in indexes.conf with frozenTimePeriodInSecs as 365 days (31536000 seconds), but there are 3 years of data stored in index.It seems not working if we just define retention time period in frozenTimePeriodInSecs. Can someone help ?&lt;/P&gt;

&lt;P&gt;$ view ./apps/launcher/local/indexes.conf&lt;BR /&gt;
[Indexname]&lt;BR /&gt;
coldPath = $SPLUNK_DB/Indexname/colddb&lt;BR /&gt;
homePath = $SPLUNK_DB/Indexname/db&lt;BR /&gt;
thawedPath = $SPLUNK_DB/Indexname/thaweddb&lt;/P&gt;

&lt;H1&gt;Maximum index total size in MB&lt;/H1&gt;

&lt;H1&gt;maxTotalDataSizeMB = 35000&lt;/H1&gt;

&lt;P&gt;frozenTimePeriodInSecs = 31536000&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:46:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405690#M14617</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2020-09-29T22:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405691#M14618</link>
      <description>&lt;P&gt;If you define the changes via the config, you will need to restart the splunk, to make effect.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 15:17:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405691#M14618</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-01-15T15:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405692#M14619</link>
      <description>&lt;P&gt;Also, the data (bucket) is frozen only when the most recent event in the bucket is older then the retention period. Sometimes, a bucket can have data for varying/larger dates-range (e.g. a bucket has data for whole 1 year) and doesn't roll until the event with newest time is older than retention period. See this for more information on the same.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Indexer/Setaretirementandarchivingpolicy#Freeze_data_when_it_grows_too_old"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Indexer/Setaretirementandarchivingpolicy#Freeze_data_when_it_grows_too_old&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 15:32:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405692#M14619</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-01-15T15:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405693#M14620</link>
      <description>&lt;P&gt;Yes Splunk has been restarted and it has most recent data in Indexes. &lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 15:40:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405693#M14620</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-01-15T15:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405694#M14621</link>
      <description>&lt;P&gt;Do i need to check configuration file precedence if the settings mentioned by me are fine.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 15:49:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405694#M14621</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-01-15T15:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405695#M14622</link>
      <description>&lt;P&gt;ok. As a good practice, pls put all your config in a custom 'app' or under 'search' app if its temporary. If the issue is resolved, pls accept the answer to close the thread.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 16:19:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405695#M14622</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-01-15T16:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405696#M14623</link>
      <description>&lt;P&gt;To clarify, you pulled this from your indexer and not the search head right?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 16:43:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405696#M14623</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-15T16:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405697#M14624</link>
      <description>&lt;P&gt;Sure. Run btool command on your indexers to see what frozenTimePeriodInSecs is effective.&lt;/P&gt;

&lt;P&gt;Go to $SPLUNK_HOME/bin and then run this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./splunk btool indexes list IndexName --debug
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This should show you what the effective configuration is and from what location.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 16:49:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405697#M14624</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-01-15T16:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405698#M14625</link>
      <description>&lt;P&gt;I pulled data from Search head and found that it has 3 years of data but when i logged in to check configuration files it shows me 1 year retention settings &lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 16:50:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405698#M14625</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-01-15T16:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405699#M14626</link>
      <description>&lt;P&gt;I pulled data from Search head and found that it has 3 years of data but when i logged in to check configuration files it shows me 1 year retention settings &lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 17:09:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405699#M14626</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-01-15T17:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405700#M14627</link>
      <description>&lt;P&gt;The stanza you posted in your original question, did that stanza come from the search head or indexer?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 17:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405700#M14627</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-15T17:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405701#M14628</link>
      <description>&lt;P&gt;I pulled data from Search head and found that it has 3 years of data but when i logged in to check configuration files it shows me 1 year retention settings &lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 17:11:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405701#M14628</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-01-15T17:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405702#M14629</link>
      <description>&lt;P&gt;Could you run this search and see what values of startEpoch and endEpoch you get for your index. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| dbinspect index=YourIndex earliest=0 | table index *Epoch splunk_server path  | convert ctime(*Epoch) | rename splunk_server as Indexer
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This command will list all the data buckets you have for your index. If endEpoch values are newer than your data retention period, then those buckets will not be frozen.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 19:35:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405702#M14629</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-01-15T19:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405703#M14630</link>
      <description>&lt;P&gt;What server did you login to check the configuration files? If you logged into the search head, then this will have no impact on retention as data lives on the indexers. &lt;/P&gt;

&lt;P&gt;Is this a standalone setup?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 19:41:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405703#M14630</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-15T19:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405704#M14631</link>
      <description>&lt;P&gt;No I checked the Indexer configuration only. Yes it is standalone setup&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 14:35:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405704#M14631</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-01-16T14:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405705#M14632</link>
      <description>&lt;P&gt;Yes it is showing 365 days only&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 14:36:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405705#M14632</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-01-16T14:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405706#M14633</link>
      <description>&lt;P&gt;&lt;A href="mailto:Hi@somesoni2..I"&gt;Hi@somesoni2..I&lt;/A&gt; think the issue is with hot buckets only. All the data is in Hot and Warm buckets and nothing has been moved to Cold buckets. Can you guide me what best config i choose so that 365 days data is always searchable and old data should be delete.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 14:38:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405706#M14633</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-01-16T14:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405707#M14634</link>
      <description>&lt;P&gt;I don't understand... How could you check the indexer config only if this is a standalone setup? &lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 14:50:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405707#M14634</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-01-16T14:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: Indexes having more data than retention period defined</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405708#M14635</link>
      <description>&lt;P&gt;Sorry i meant it is not clustered environment&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 14:54:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Indexes-having-more-data-than-retention-period-defined/m-p/405708#M14635</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-01-16T14:54:09Z</dc:date>
    </item>
  </channel>
</rss>

