<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: send log to bucket s3 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/send-log-to-bucket-s3/m-p/680327#M113674</link>
    <description>&lt;P&gt;Indexers will automatically copy buckets from local storage to SmartStore/S3 when they roll from hot to warm.&amp;nbsp; You can try to tune the hot bucket lifetime to 30 days, but I don't recommend it.&amp;nbsp; Let them roll normally and size your SmartStore cache so it's large enough to hold 30 days' of data.&lt;/P&gt;&lt;P&gt;Use the frozenTimePeriodInSecs setting in indexes.conf to specify the lifetime of the data.&amp;nbsp; Buckets will be removed from S3 when the newest event in the bucket is older than the specified time.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2024 20:20:03 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-03-11T20:20:03Z</dc:date>
    <item>
      <title>send log to bucket s3</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/send-log-to-bucket-s3/m-p/680314#M113673</link>
      <description>&lt;P&gt;hello all,&lt;/P&gt;&lt;P&gt;I would need the logs to be sent to my S3 bucket smartstorage after 1 month from my security index, but they should still be accessible for another 5 months.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 17:27:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/send-log-to-bucket-s3/m-p/680314#M113673</guid>
      <dc:creator>toporagno</dc:creator>
      <dc:date>2024-03-11T17:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: send log to bucket s3</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/send-log-to-bucket-s3/m-p/680327#M113674</link>
      <description>&lt;P&gt;Indexers will automatically copy buckets from local storage to SmartStore/S3 when they roll from hot to warm.&amp;nbsp; You can try to tune the hot bucket lifetime to 30 days, but I don't recommend it.&amp;nbsp; Let them roll normally and size your SmartStore cache so it's large enough to hold 30 days' of data.&lt;/P&gt;&lt;P&gt;Use the frozenTimePeriodInSecs setting in indexes.conf to specify the lifetime of the data.&amp;nbsp; Buckets will be removed from S3 when the newest event in the bucket is older than the specified time.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2024 20:20:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/send-log-to-bucket-s3/m-p/680327#M113674</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-03-11T20:20:03Z</dc:date>
    </item>
  </channel>
</rss>

