<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Understanding Splunk Index Retention in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659118#M27516</link>
    <description>&lt;P&gt;I think I should also have mentioned that I have stopped ingestion onto this index for now. Until I figure out how to reduce the storage/clean the data.&lt;/P&gt;</description>
    <pubDate>Fri, 29 Sep 2023 18:41:41 GMT</pubDate>
    <dc:creator>felipesodre</dc:creator>
    <dc:date>2023-09-29T18:41:41Z</dc:date>
    <item>
      <title>Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659115#M27515</link>
      <description>&lt;P&gt;Hi, and sorry if this question was already answered in any other thread.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for the help.&lt;/P&gt;&lt;P&gt;I had an index in which the current size was over 10 GB,&amp;nbsp; for deleting the data I tried to reduce it's max size and searchable retention.&lt;/P&gt;&lt;P&gt;My question is what is going to happen with the data? Will it be deleted from the servers or archived? I am confused because I am seeing the event counts stuck with the same value as it was before changing the retention config.&lt;/P&gt;&lt;P&gt;Previous index config:&lt;/P&gt;&lt;P&gt;Current Size 10 GB, Max Size: 0, Event Count: 10M, Earliest Event: 5 Months, Latest Event: 1 day, Searchable Retention: 365 days,&amp;nbsp; Archive Retention: blank, Self Storage: blank, Status: enabled&lt;/P&gt;&lt;P&gt;Then, I changed the parameters&amp;nbsp; "Max Size" to&amp;nbsp; "200 MB" and "Searchable Retention" to "1 Day".&lt;/P&gt;&lt;P&gt;Besides, when running the following query,&amp;nbsp;&amp;nbsp;I see the warm storage size pretty much with the same size (bouncing a few mbs).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|dbinspect index=_internal *&amp;lt;index-name&amp;gt;* 
| stats sum(sizeOnDiskMB) by state&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 19:30:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659115#M27515</guid>
      <dc:creator>felipesodre</dc:creator>
      <dc:date>2023-09-29T19:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659118#M27516</link>
      <description>&lt;P&gt;I think I should also have mentioned that I have stopped ingestion onto this index for now. Until I figure out how to reduce the storage/clean the data.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 18:41:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659118#M27516</guid>
      <dc:creator>felipesodre</dc:creator>
      <dc:date>2023-09-29T18:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659143#M27517</link>
      <description>&lt;P&gt;&lt;A class="" href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352" target="_self"&gt;&lt;SPAN class=""&gt;gcusello&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;Any guidance?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 21:39:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659143#M27517</guid>
      <dc:creator>felipesodre</dc:creator>
      <dc:date>2023-09-29T21:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659144#M27518</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1406"&gt;@woodcock&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 22:23:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659144#M27518</guid>
      <dc:creator>felipesodre</dc:creator>
      <dc:date>2023-09-29T22:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659145#M27519</link>
      <description>&lt;P&gt;There is so much "depends" here that we could open a nursing home.&amp;nbsp; Are you using SmartStore?&amp;nbsp; Are you using indexer clustering?&amp;nbsp; What are your SF/RF settings?&amp;nbsp; Are you using Volume settings for your indexers?&amp;nbsp; Are you Splunk Cloud?&amp;nbsp; What is the "btool" output for your indexes.conf from one of your indexers?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 22:35:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659145#M27519</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-09-29T22:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659146#M27520</link>
      <description>&lt;P&gt;Hi, thank you for replying back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Settings:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SmartStore: No&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Indexer clustering: No&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SF/RF Settings Splunk: SF=2, RF=3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Volume settings: Default settings&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk Cloud: Yes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Unfortunately, I am unable to run the "btool".&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;However, I am able to run the following rest API query to gather the info from specific parameters for the mentioned index:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;| rest /services/data/indexes&lt;BR /&gt;| join type=outer title [&lt;BR /&gt;| rest splunk_server=n00bserver /services/data/indexes-extended&lt;BR /&gt;]&lt;BR /&gt;| search title=*&lt;BR /&gt;| eval retentionInDays=frozenTimePeriodInSecs/86400&lt;BR /&gt;| table *&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;What should be the parameters to look for?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 23:03:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659146#M27520</guid>
      <dc:creator>felipesodre</dc:creator>
      <dc:date>2023-09-29T23:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659150#M27521</link>
      <description>&lt;P&gt;I am so confused as to why there are still buckets with data in which the endEpochTime is older than the "Searchable Retention"&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="felipesodre_2-1696030673541.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27386i1FD207E7B5DE36A8/image-size/large?v=v2&amp;amp;px=999" role="button" title="felipesodre_2-1696030673541.png" alt="felipesodre_2-1696030673541.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 23:39:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659150#M27521</guid>
      <dc:creator>felipesodre</dc:creator>
      <dc:date>2023-09-29T23:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659151#M27522</link>
      <description>&lt;P&gt;Probably because there are also events (at least one) in that bucket that are younger.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Sep 2023 00:26:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659151#M27522</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-09-30T00:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659152#M27523</link>
      <description>&lt;P&gt;So, is it safe to assume that if no new data is ingested into this index the data should be gone by tomorrow (the same time I changed the config)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;</description>
      <pubDate>Sat, 30 Sep 2023 00:33:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659152#M27523</guid>
      <dc:creator>felipesodre</dc:creator>
      <dc:date>2023-09-30T00:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659172#M27524</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/59510"&gt;@felipesodre&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;when your bucket completely exceed the retention time (also the earliest event in the bucket) or the bucket reaches the maxSize it can be discarded or moved to offline in a different folder.&lt;/P&gt;&lt;P&gt;As described at &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.1/Admin/Indexesconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.1/Admin/Indexesconf&lt;/A&gt;&amp;nbsp;, it dependa on the parameter coldToFrozenScript that specifies a script to run when data is to leave the splunk index system, in other words, what happens to the bucket after the retention period.&lt;/P&gt;&lt;P&gt;If, using a script, you move your Cold Bucket to offline, you can re use them copying them in the Thawed path.&lt;/P&gt;&lt;P&gt;Otherwise you can discard them and the entire bucket is deleted.&lt;/P&gt;&lt;P&gt;You can find more details in this document&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.1/Indexer/Setaretirementandarchivingpolicy" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.1/Indexer/Setaretirementandarchivingpolicy&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 30 Sep 2023 10:52:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659172#M27524</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-30T10:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659208#M27525</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/59510"&gt;@felipesodre&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Sep 2023 16:06:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659208#M27525</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-09-30T16:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659209#M27526</link>
      <description>&lt;P&gt;Thank you for clarifying that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Sep 2023 16:09:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659209#M27526</guid>
      <dc:creator>felipesodre</dc:creator>
      <dc:date>2023-09-30T16:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659228#M27527</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;Small correction - bucket is eligible for rotation to frozen if _latest_ event in it is older than the retention limit, not earliest.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Sep 2023 21:44:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659228#M27527</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-09-30T21:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding Splunk Index Retention</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659237#M27528</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/59510"&gt;@felipesodre&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;correct, sorry!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 01 Oct 2023 08:18:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Understanding-Splunk-Index-Retention/m-p/659237#M27528</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-10-01T08:18:02Z</dc:date>
    </item>
  </channel>
</rss>

