<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: retention policy in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/retention-policy/m-p/674204#M112849</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264007"&gt;@jbates58&lt;/a&gt;&amp;nbsp;Yes, at times the retention policy may give difficult times.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;in DMC Server, Pls check this...&amp;nbsp; Settings &amp;gt; Monitoring Console &amp;gt; Indexing &amp;gt; Indexes and Volumes &amp;gt; Index Detail: Instance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk-retention-policy.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28920iD81D836927B4A92D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk-retention-policy.jpg" alt="Splunk-retention-policy.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;EDIT - Pls check the docs at&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.2/Admin/Indexesconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splu nk/9.1.2/Admin/Indexesconf&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;one thing to remember -&amp;nbsp;frozenTimePeriodInSecs vs maxTotalDataSizeMB - can give confusion as well (i remember whichever comes first will work and take precedence over the other)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jan 2024 02:01:09 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2024-01-15T02:01:09Z</dc:date>
    <item>
      <title>retention policy</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/retention-policy/m-p/674201#M112848</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have tried looking over the documentation for this, but I am super confused. And really struggling to wrap my head around this.&lt;/P&gt;&lt;P&gt;I have an environment where Splunk is ingesting syslog from 2 firewalls. The logs are only audit / management related, and these need to be sent to a sperate server for compliance (hence splunk).&lt;/P&gt;&lt;P&gt;I&amp;nbsp; want to configure a retention policy where this data is deleted after 1 year, as that is the specific requirement.&lt;/P&gt;&lt;P&gt;From what i can tell, i just need to add the "frozentimeinseconds" line to the index conf file for the "main" index (as this is where the events are going)&lt;/P&gt;&lt;P&gt;Current ingestion is ~150,000 events per day. And daily ingestion is ~30-35MB.However, this is subject to change in the future as more firewalls come online etc..&lt;/P&gt;&lt;P&gt;There is plenty of storage available. However the requirement is just 1 year of searchable data.&lt;/P&gt;&lt;P&gt;But I keep seeing things about hot/warm/cold/frozen etc.. and i just dont get it. All thats needed is 1 year of searchable data, anything older than (time.now() - 365 days) can be deleted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone please assist me with what i need to do to make this work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 00:05:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/retention-policy/m-p/674201#M112848</guid>
      <dc:creator>jbates58</dc:creator>
      <dc:date>2024-01-15T00:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: retention policy</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/retention-policy/m-p/674204#M112849</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264007"&gt;@jbates58&lt;/a&gt;&amp;nbsp;Yes, at times the retention policy may give difficult times.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;in DMC Server, Pls check this...&amp;nbsp; Settings &amp;gt; Monitoring Console &amp;gt; Indexing &amp;gt; Indexes and Volumes &amp;gt; Index Detail: Instance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk-retention-policy.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28920iD81D836927B4A92D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk-retention-policy.jpg" alt="Splunk-retention-policy.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;EDIT - Pls check the docs at&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.2/Admin/Indexesconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splu nk/9.1.2/Admin/Indexesconf&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;one thing to remember -&amp;nbsp;frozenTimePeriodInSecs vs maxTotalDataSizeMB - can give confusion as well (i remember whichever comes first will work and take precedence over the other)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 02:01:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/retention-policy/m-p/674204#M112849</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-01-15T02:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: retention policy</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/retention-policy/m-p/674207#M112850</link>
      <description>&lt;P&gt;Here is the contents of that page. I have redacted out a little bit of info relating to the environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jbates58_0-1705284047904.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28921i03625AAD3E5BC49C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jbates58_0-1705284047904.png" alt="jbates58_0-1705284047904.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jbates58_1-1705284129840.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28922iA9D76398928972A7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jbates58_1-1705284129840.png" alt="jbates58_1-1705284129840.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 02:02:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/retention-policy/m-p/674207#M112850</guid>
      <dc:creator>jbates58</dc:creator>
      <dc:date>2024-01-15T02:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: retention policy</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/retention-policy/m-p/674218#M112854</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264007"&gt;@jbates58&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;at first on the server containin the indexes, don't use the main index, but create a custom index (e.g. firewalls)&lt;/P&gt;&lt;P&gt;then for this new index define the retention you want (one year).&lt;/P&gt;&lt;P&gt;Then assign the new index name to the inputs that you should have on your Forwarders.&lt;/P&gt;&lt;P&gt;At least, when you'll ingest more logs, you should monitor your index to undertand if the dimension you configured is correct or if you need to enlarge it.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 07:28:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/retention-policy/m-p/674218#M112854</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-15T07:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: retention policy</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/retention-policy/m-p/674220#M112855</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;getting exact retention time for e.g. 1y in splunk could be almost mission impossible &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;There is several parameters how splunk define when it removes those&amp;nbsp;&lt;STRONG&gt;buckets,&lt;/STRONG&gt; which has&amp;nbsp;&lt;STRONG&gt;all&lt;/STRONG&gt; events older than your defined retention time! You must understand than when splunk calculate retention in reality it's for all events in bucket! It's not event based, as a smallest storage unit is a&amp;nbsp;&lt;EM&gt;bucket&lt;/EM&gt; not an&amp;nbsp;&lt;EM&gt;event&lt;/EM&gt;. Practically this means that splunk can remove bucket, when all events in that bucket has older than your defined retention.&lt;/P&gt;&lt;P&gt;In your case, you have quite low event volume, which means that you could have one bucket, which contains events from several months max(15GB divide 30MB divided by #hot buckets for that index ). Usually you have several (default is 3) active hot buckets (per search peer) at same time, where splunk can write new events. Default for keeping a bucket as hot is 90d or when it's come full or when you restart splunk. There are also some other parameters which could affect this!&lt;/P&gt;&lt;P&gt;Here is some links where you could learn more how this is actually working:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://conf.splunk.com/files/2017/slides/splunk-data-life-cycle-determining-when-and-where-to-roll-data.pdf" target="_blank"&gt;https://conf.splunk.com/files/2017/slides/splunk-data-life-cycle-determining-when-and-where-to-roll-data.pdf&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.2/Indexer/Bucketsandclusters" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.2/Indexer/Bucketsandclusters&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/How-can-I-find-the-data-retention-and-indexers-involved/m-p/645365/highlight/true" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/How-can-I-find-the-data-retention-and-indexers-involved/m-p/645365/highlight/true&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Indexes-configuration/m-p/564276" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Indexes-configuration/m-p/564276&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/624944#M14863" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Enterprise/Splunk-shows-only-9-months-270-days-data-How-do-I-increase-the/m-p/624944#M14863&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/What-counts-for-Splunk-retention-time-if-events-come-in-with-a/td-p/601655" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/What-counts-for-Splunk-retention-time-if-events-come-in-with-a/td-p/601655&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 07:45:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/retention-policy/m-p/674220#M112855</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-01-15T07:45:24Z</dc:date>
    </item>
  </channel>
</rss>

