<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Retention Policy in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Retention-Policy/m-p/517164#M17757</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64690"&gt;@btshivanand&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in Splunk, events are stored in buckets and retention is managed at bucket level not at event level.&lt;/P&gt;&lt;P&gt;In other words, a full bucket is deleted (or moved in a different folder) when the latest events exceeds the retention period.&lt;/P&gt;&lt;P&gt;For this reason you have buckets with events that exceed the retention period because in the same bucket there's at least one event still in the retention period.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 01 Sep 2020 07:00:49 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2020-09-01T07:00:49Z</dc:date>
    <item>
      <title>Data Retention Policy</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Retention-Policy/m-p/517159#M17755</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;&lt;P&gt;We defined 35 days retention for real time indexes in splunk.I see that retention are not happening strictly.Some of the old&amp;nbsp; events are not getting deleted .We have around 200 days data for some indexes .Also i see that for some indexes only January month data is present.I also cross checked with events time and indexed time. they are old data and not deleted due to retention policy.Now i have two concerns&amp;nbsp;&lt;/P&gt;&lt;P&gt;1)How to maintain strict 35 days retention's ?&lt;/P&gt;&lt;P&gt;2)Any idea why January month data is present and it is not getting deleted even though buckets are rolling out? and how they can be deleted with retention's.&lt;/P&gt;&lt;P&gt;Below are my settings for one index.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[rt]&lt;BR /&gt;# 80 GB a day / 14 days in warm / 35 day retention&lt;BR /&gt;homePath = volume:hot/rt/db&lt;BR /&gt;coldPath = volume:cold/rt/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/rt/thaweddb&lt;BR /&gt;homePath.maxDataSizeMB = 500000&lt;BR /&gt;coldPath.maxDataSizeMB = 1000000&lt;BR /&gt;maxWarmDBCount = 300&lt;BR /&gt;frozenTimePeriodInSecs = 3024000&lt;BR /&gt;maxDataSize = auto_high_volume&lt;BR /&gt;maxTotalDataSizeMB = 150000&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,Shivanand&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 06:43:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Retention-Policy/m-p/517159#M17755</guid>
      <dc:creator>btshivanand</dc:creator>
      <dc:date>2020-09-01T06:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Data Retention Policy</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Retention-Policy/m-p/517164#M17757</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64690"&gt;@btshivanand&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in Splunk, events are stored in buckets and retention is managed at bucket level not at event level.&lt;/P&gt;&lt;P&gt;In other words, a full bucket is deleted (or moved in a different folder) when the latest events exceeds the retention period.&lt;/P&gt;&lt;P&gt;For this reason you have buckets with events that exceed the retention period because in the same bucket there's at least one event still in the retention period.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 07:00:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Retention-Policy/m-p/517164#M17757</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-01T07:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Data Retention Policy</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Retention-Policy/m-p/517176#M17760</link>
      <description>&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;I see only jan month events for one of the index and there is no events are present till july.. I understand events are stored in the bucket and they will deleted once the buckets are rolled out.This is something strange i see.. how i need to get rid of this?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 07:36:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Retention-Policy/m-p/517176#M17760</guid>
      <dc:creator>btshivanand</dc:creator>
      <dc:date>2020-09-01T07:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Data Retention Policy</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Retention-Policy/m-p/517179#M17761</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64690"&gt;@btshivanand&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;in my opinion, leave it alone and it will fix by itself.&lt;BR /&gt;As I told you, retention management is done at bucket level.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If you really want to take action, you could:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;reduce the retention of that Index,&lt;/LI&gt;&lt;LI&gt;restart Splunk,&lt;/LI&gt;&lt;LI&gt;when the January events are cleared, reset the retention to the correct value,&lt;/LI&gt;&lt;LI&gt;and restart Splunk again.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;But in this way there the risk to loose some events.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 07:52:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Retention-Policy/m-p/517179#M17761</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-01T07:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: Data Retention Policy</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Retention-Policy/m-p/517181#M17762</link>
      <description>&lt;P&gt;Ok.. Better to leave as it is.. But any suggestion to maintain the retention for other index we have..They are also helding more number of data.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 08:07:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Retention-Policy/m-p/517181#M17762</guid>
      <dc:creator>btshivanand</dc:creator>
      <dc:date>2020-09-01T08:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Data Retention Policy</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Retention-Policy/m-p/517190#M17763</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/64690"&gt;@btshivanand&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;for the second question, if you have more data, probably you'll have less problems because the presence of more data has the consequence of a minor timerange (between the older and the newest events) for each bucket, that means that this problem will disappear.&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 08:40:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Retention-Policy/m-p/517190#M17763</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-01T08:40:24Z</dc:date>
    </item>
  </channel>
</rss>

