<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Old log getting stored as .csv format even before retention? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Old-log-getting-stored-as-csv-format-even-before-retention/m-p/651270#M110616</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We have defined the index retention as 420 days but when we are trying to access the logs those are in .csv format not as event-value format.&lt;/P&gt;
&lt;P&gt;PFA of index details and below indexes.conf confuguration if that index.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[rt_efb]&lt;BR /&gt;# 250MB a day / 35 days in warm / 460 days retention / 8 GB max index size&lt;BR /&gt;homePath = volume:hot/rt_efb/db&lt;BR /&gt;coldPath = volume:cold/rt_efb/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/rt_efb/thaweddb&lt;BR /&gt;#set to 5 days, +- 5days padding&lt;BR /&gt;maxHotSpanSecs = 432000&lt;BR /&gt;#set to 2 hot buckets&lt;BR /&gt;maxHotBuckets = 2&lt;BR /&gt;homePath.maxDataSizeMB = 2500&lt;BR /&gt;coldPath.maxDataSizeMB = 5500&lt;BR /&gt;frozenTimePeriodInSecs = 39744000&lt;BR /&gt;maxTotalDataSizeMB = 26000&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please suggest us on this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Anil&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jul 2023 17:54:46 GMT</pubDate>
    <dc:creator>anil28</dc:creator>
    <dc:date>2023-07-21T17:54:46Z</dc:date>
    <item>
      <title>Old log getting stored as .csv format even before retention?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Old-log-getting-stored-as-csv-format-even-before-retention/m-p/651270#M110616</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;We have defined the index retention as 420 days but when we are trying to access the logs those are in .csv format not as event-value format.&lt;/P&gt;
&lt;P&gt;PFA of index details and below indexes.conf confuguration if that index.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[rt_efb]&lt;BR /&gt;# 250MB a day / 35 days in warm / 460 days retention / 8 GB max index size&lt;BR /&gt;homePath = volume:hot/rt_efb/db&lt;BR /&gt;coldPath = volume:cold/rt_efb/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/rt_efb/thaweddb&lt;BR /&gt;#set to 5 days, +- 5days padding&lt;BR /&gt;maxHotSpanSecs = 432000&lt;BR /&gt;#set to 2 hot buckets&lt;BR /&gt;maxHotBuckets = 2&lt;BR /&gt;homePath.maxDataSizeMB = 2500&lt;BR /&gt;coldPath.maxDataSizeMB = 5500&lt;BR /&gt;frozenTimePeriodInSecs = 39744000&lt;BR /&gt;maxTotalDataSizeMB = 26000&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please suggest us on this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Anil&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 17:54:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Old-log-getting-stored-as-csv-format-even-before-retention/m-p/651270#M110616</guid>
      <dc:creator>anil28</dc:creator>
      <dc:date>2023-07-21T17:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: old log getting stored as .csv format even before retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Old-log-getting-stored-as-csv-format-even-before-retention/m-p/651468#M110645</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;What you are meaning with "&lt;SPAN&gt;those are in .csv format"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As you are using volumes (it's best practices) there are also those volume sizing&amp;nbsp;&lt;/SPAN&gt;parameters which could also affect what you really have on disk.&lt;/P&gt;&lt;P&gt;btw. you cannot define how long events are in warm. There is no that kind of parameter. Only things what you can do is define how many buckets can be on warm state and how much space they have. Of course also max volume is one constraint for all indexes in that volume.&lt;/P&gt;&lt;P&gt;As there are already quite many answers about this issue, You could look those e.g. with google like "site:community.splunk.com&amp;nbsp;splunk event retention parameters" or something similar.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 11:57:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Old-log-getting-stored-as-csv-format-even-before-retention/m-p/651468#M110645</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-07-21T11:57:48Z</dc:date>
    </item>
  </channel>
</rss>

