<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to troubleshoot why 90 data data retention configuration is not being applied? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-90-data-data-retention-configuration-is/m-p/126394#M26020</link>
    <description>&lt;P&gt;I want to freeze all data older than 90 days.&lt;/P&gt;

&lt;P&gt;My /opt/splunk/etc/system/local/indexes.conf file looks like this&lt;/P&gt;

&lt;P&gt;[default]&lt;/P&gt;

&lt;P&gt;[_audit]&lt;/P&gt;

&lt;P&gt;[main]&lt;BR /&gt;
rotatePeriodInSecs = 60&lt;BR /&gt;
coldToFrozenDir = /logs/frozen&lt;BR /&gt;
maxTotalDataSizeMB = 400000&lt;BR /&gt;
frozenTimePeriodInSecs = 7776000&lt;/P&gt;

&lt;P&gt;But I still have data that is up to six months old. Can someone suggest other places to look to correct this?&lt;/P&gt;</description>
    <pubDate>Mon, 17 Nov 2014 20:07:42 GMT</pubDate>
    <dc:creator>rblalock</dc:creator>
    <dc:date>2014-11-17T20:07:42Z</dc:date>
    <item>
      <title>How to troubleshoot why 90 data data retention configuration is not being applied?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-90-data-data-retention-configuration-is/m-p/126394#M26020</link>
      <description>&lt;P&gt;I want to freeze all data older than 90 days.&lt;/P&gt;

&lt;P&gt;My /opt/splunk/etc/system/local/indexes.conf file looks like this&lt;/P&gt;

&lt;P&gt;[default]&lt;/P&gt;

&lt;P&gt;[_audit]&lt;/P&gt;

&lt;P&gt;[main]&lt;BR /&gt;
rotatePeriodInSecs = 60&lt;BR /&gt;
coldToFrozenDir = /logs/frozen&lt;BR /&gt;
maxTotalDataSizeMB = 400000&lt;BR /&gt;
frozenTimePeriodInSecs = 7776000&lt;/P&gt;

&lt;P&gt;But I still have data that is up to six months old. Can someone suggest other places to look to correct this?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Nov 2014 20:07:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-90-data-data-retention-configuration-is/m-p/126394#M26020</guid>
      <dc:creator>rblalock</dc:creator>
      <dc:date>2014-11-17T20:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why 90 data data retention configuration is not being applied?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-90-data-data-retention-configuration-is/m-p/126395#M26021</link>
      <description>&lt;P&gt;First, verify the value stuck by running &lt;CODE&gt;splunk cmd btool indexes list main&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;Then, check if the bucket containing that old data happens to also contain newer data. It'll get rolled when the youngest event is older than the frozen period.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Nov 2014 22:04:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-90-data-data-retention-configuration-is/m-p/126395#M26021</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-11-17T22:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why 90 data data retention configuration is not being applied?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-90-data-data-retention-configuration-is/m-p/126396#M26022</link>
      <description>&lt;P&gt;See below link which explains various properties involved in setting up the retention policy and bucket life cycle.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Deploy:BucketRotationAndRetention"&gt;http://wiki.splunk.com/Deploy:BucketRotationAndRetention&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Basically, you need to setup maxHotSpanSecs and  maxWarmDBCount to values so that your data bucket is getting rolled over to frozen. It will be deleted only after it's moved to frozen state.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Nov 2014 23:56:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-90-data-data-retention-configuration-is/m-p/126396#M26022</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-11-17T23:56:44Z</dc:date>
    </item>
  </channel>
</rss>

