<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time based retention time, without a thawed path in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Time-based-retention-time-without-a-thawed-path/m-p/701208#M116053</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228376"&gt;@avoelk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you don't need to allocate any disk space: the thawed path is only a mount point that you can use to recover frozen buckets, if you don't need it, you must only define the mount point (the thawed_path) in indexes.conf and then you don't need to allocate any disk space.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 07 Oct 2024 14:59:22 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-10-07T14:59:22Z</dc:date>
    <item>
      <title>Time based retention time, without a thawed path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-based-retention-time-without-a-thawed-path/m-p/701200#M116050</link>
      <description>&lt;P&gt;I'm trying to configure the indexes.conf in such a way that its data retention is exactly 180 days and then does NOT get frozen, but gets deleted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried to set it with frozenTimePeriodInSecs = 15552000 but now I get the following error:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Validation errors are present in the bundle. Errors=peer=XXX, stanza=someidx Required parameter=thawedPath not configured;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so I HAVE TO put a thawed path in it even tho I don't want to freeze anything? how does that make sense?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards for a clarification!&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 13:57:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-based-retention-time-without-a-thawed-path/m-p/701200#M116050</guid>
      <dc:creator>avoelk</dc:creator>
      <dc:date>2024-10-07T13:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: Time based retention time, without a thawed path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-based-retention-time-without-a-thawed-path/m-p/701202#M116051</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228376"&gt;@avoelk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;yes, it's a required parameter even if you don't want to restore thawed buckets.&lt;/P&gt;&lt;P&gt;Remember in Splunk the retention period is managed at bucket level, in other words, a bucket is deleted (or frozen) only when the latest event is older than the retention period, this means that you'll surely have in your buckets events older than the retention period, because they are in a bucket with younger events.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 14:10:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-based-retention-time-without-a-thawed-path/m-p/701202#M116051</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-10-07T14:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Time based retention time, without a thawed path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-based-retention-time-without-a-thawed-path/m-p/701204#M116052</link>
      <description>&lt;P&gt;Hi Giuseppe and thanks for the swift answer!&lt;/P&gt;&lt;P&gt;But how does it behave if I don't want to allocate a specific diskspace for thawed files/frozen files?&amp;nbsp;&lt;/P&gt;&lt;P&gt;So there is no way to just have a retention of 180 days and afterwards it will be deleted or did I get something of your answer wrong?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 14:42:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-based-retention-time-without-a-thawed-path/m-p/701204#M116052</guid>
      <dc:creator>avoelk</dc:creator>
      <dc:date>2024-10-07T14:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Time based retention time, without a thawed path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-based-retention-time-without-a-thawed-path/m-p/701208#M116053</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228376"&gt;@avoelk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you don't need to allocate any disk space: the thawed path is only a mount point that you can use to recover frozen buckets, if you don't need it, you must only define the mount point (the thawed_path) in indexes.conf and then you don't need to allocate any disk space.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 14:59:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-based-retention-time-without-a-thawed-path/m-p/701208#M116053</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-10-07T14:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: Time based retention time, without a thawed path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-based-retention-time-without-a-thawed-path/m-p/701210#M116054</link>
      <description>&lt;P&gt;Thawed path is the directory in which you'd have to manually put the data to be thawed (or where Splunk puts it after thawing; I don't remember I don't generally thaw buckets). It doesn't have anything to do with the freezing process. If you don't define frozen path (and freeze script) the data will get deleted when rolled to frozen.&lt;/P&gt;&lt;P&gt;And be aware of what &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; said - data is rolled on a per bucket basis which means that "resolution" of the bucket rolling process depends on the contents of the buckets - data is being rolled to frozen when _newest_ event in a bucket is older than the retention period. That can be important especially in case of quarantine buckets.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 15:05:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-based-retention-time-without-a-thawed-path/m-p/701210#M116054</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-10-07T15:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: Time based retention time, without a thawed path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Time-based-retention-time-without-a-thawed-path/m-p/701211#M116055</link>
      <description>&lt;P&gt;Thanks a lot !&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 15:06:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Time-based-retention-time-without-a-thawed-path/m-p/701211#M116055</guid>
      <dc:creator>avoelk</dc:creator>
      <dc:date>2024-10-07T15:06:21Z</dc:date>
    </item>
  </channel>
</rss>

