<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Retention Time Question in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162469#M32983</link>
    <description>&lt;P&gt;system     maxConcurrentOptimizes = 3&lt;BR /&gt;
system     maxDataSize = auto_high_volume&lt;BR /&gt;
system     maxHotBuckets = 3&lt;BR /&gt;
system     maxHotIdleSecs = 0&lt;BR /&gt;
system     maxHotSpanSecs = 7776000&lt;BR /&gt;
system     maxMemMB = 5&lt;BR /&gt;
system     maxMetaEntries = 1000000&lt;BR /&gt;
system     maxRunningProcessGroups = 20&lt;BR /&gt;
system     maxRunningProcessGroupsLowPriority = 1&lt;BR /&gt;
system     maxTotalDataSizeMB = 1000000&lt;BR /&gt;
system     maxWarmDBCount = 300&lt;BR /&gt;
system     memPoolMB = auto&lt;BR /&gt;
system     minRawFileSyncSecs = disable&lt;BR /&gt;
system     partialServiceMetaPeriod = 0&lt;BR /&gt;
system     quarantineFutureSecs = 2592000&lt;BR /&gt;
system     quarantinePastSecs = 77760000&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 15:23:56 GMT</pubDate>
    <dc:creator>hartfoml</dc:creator>
    <dc:date>2020-09-28T15:23:56Z</dc:date>
    <item>
      <title>Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162464#M32978</link>
      <description>&lt;P&gt;I have this setting in my index.conf&lt;/P&gt;

&lt;P&gt;frozenTimePeriodInSecs = 48211200&lt;/P&gt;

&lt;P&gt;As I understand it this should keep data in the index for about 1.53 years&lt;/P&gt;

&lt;P&gt;I do not have any data in the index past January 9th of this year.  Somehow the data has rolled out or has it?&lt;/P&gt;

&lt;P&gt;Also if the data really has rolled out, then I need to restore from an old copy of the index back from January.&lt;/P&gt;

&lt;P&gt;Can you point me to the process doc to connect an old copy of the index and extract the logs (Many Millions of lines - Firewall Logs) and put the logs back into the online index.&lt;/P&gt;

&lt;P&gt;Thanks for the help.  &lt;/P&gt;

&lt;P&gt;Support said they wouldn't be able to help until tomorrow and needed a diag. &lt;/P&gt;

&lt;P&gt;A diag? for what, to find out what happened 11 months ago?&lt;/P&gt;

&lt;P&gt;How would I check to see what is rolling out of the firewall index?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 17:26:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162464#M32978</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-12-02T17:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162465#M32979</link>
      <description>&lt;P&gt;The file should be "indexes.conf". Where is this file located? &lt;/P&gt;

&lt;P&gt;You can check the settings by using: &lt;CODE&gt;$SPLUNK_HOME/bin/splunk cmd btool --debug indexes list YOUR_INDEX_NAME&lt;/CODE&gt;. This will show you from what file a setting was included, and what all the options are for that index. Do this on the indexers.&lt;/P&gt;

&lt;P&gt;If you have really rolled data - you will need to restore the buckets - copy and paste will do as long as the bucket ids don't collide.&lt;/P&gt;

&lt;P&gt;EDIT AND UPDATE:&lt;/P&gt;

&lt;P&gt;So according to your last comment - you are maxing your index at &amp;lt;1TB, so it will roll off data when the index reaches that threshold. Set your &lt;CODE&gt;maxTotalDataSizeMB = 104857600&lt;/CODE&gt;. You will then start storing your data up to 1.5 years OR 100 TB, which ever comes FIRST.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 17:36:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162465#M32979</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-12-02T17:36:25Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162466#M32980</link>
      <description>&lt;P&gt;/opt/splunk/etc/system/local/indexes.conf&lt;/P&gt;

&lt;P&gt;Sorry typing too fast for my own good.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 17:38:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162466#M32980</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-12-02T17:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162467#M32981</link>
      <description>&lt;P&gt;What does the output of that command show? What version are you using?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 17:39:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162467#M32981</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-12-02T17:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162468#M32982</link>
      <description>&lt;P&gt;system     [firewall]&lt;BR /&gt;
system     assureUTF8 = false&lt;BR /&gt;
system     blockSignSize = 0&lt;BR /&gt;
system     blockSignatureDatabase = _blocksignature&lt;BR /&gt;
system     coldPath = $SPLUNK_DB/firewall/colddb&lt;BR /&gt;
system     coldToFrozenDir = &lt;BR /&gt;
system     coldToFrozenScript = &lt;BR /&gt;
system     compressRawdata = true&lt;BR /&gt;
system     defaultDatabase = main&lt;BR /&gt;
system     enableOnlineBucketRepair = true&lt;BR /&gt;
system     enableRealtimeSearch = true&lt;BR /&gt;
system     frozenTimePeriodInSecs = 48211200&lt;BR /&gt;
system     homePath = $SPLUNK_DB/firewall/db&lt;BR /&gt;
system     indexThreads = auto&lt;BR /&gt;
system     maxBloomBackfillBucketAge = 30d&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:23:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162468#M32982</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2020-09-28T15:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162469#M32983</link>
      <description>&lt;P&gt;system     maxConcurrentOptimizes = 3&lt;BR /&gt;
system     maxDataSize = auto_high_volume&lt;BR /&gt;
system     maxHotBuckets = 3&lt;BR /&gt;
system     maxHotIdleSecs = 0&lt;BR /&gt;
system     maxHotSpanSecs = 7776000&lt;BR /&gt;
system     maxMemMB = 5&lt;BR /&gt;
system     maxMetaEntries = 1000000&lt;BR /&gt;
system     maxRunningProcessGroups = 20&lt;BR /&gt;
system     maxRunningProcessGroupsLowPriority = 1&lt;BR /&gt;
system     maxTotalDataSizeMB = 1000000&lt;BR /&gt;
system     maxWarmDBCount = 300&lt;BR /&gt;
system     memPoolMB = auto&lt;BR /&gt;
system     minRawFileSyncSecs = disable&lt;BR /&gt;
system     partialServiceMetaPeriod = 0&lt;BR /&gt;
system     quarantineFutureSecs = 2592000&lt;BR /&gt;
system     quarantinePastSecs = 77760000&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:23:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162469#M32983</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2020-09-28T15:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162470#M32984</link>
      <description>&lt;P&gt;system     rawChunkSizeBytes = 131072&lt;BR /&gt;
system     rotatePeriodInSecs = 60&lt;BR /&gt;
system     serviceMetaPeriod = 25&lt;BR /&gt;
system     suppressBannerList = &lt;BR /&gt;
system     sync = 0&lt;BR /&gt;
system     syncMeta = true&lt;BR /&gt;
system     thawedPath = $SPLUNK_DB/firewall/thaweddb&lt;BR /&gt;
system     throttleCheckPeriod = 15&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 17:42:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162470#M32984</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-12-02T17:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162471#M32985</link>
      <description>&lt;P&gt;This shows that your frozen time is correct. How are you determining that the data is not there? Via Search GUI or manually looking in the db files?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 17:45:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162471#M32985</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-12-02T17:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162472#M32986</link>
      <description>&lt;P&gt;Search GUI&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 18:06:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162472#M32986</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-12-02T18:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162473#M32987</link>
      <description>&lt;P&gt;Try these commands and see what returns (run them from &lt;CODE&gt;$SPLUNK_DB/firewall/colddb&lt;/CODE&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;touch --date "2013-01-02" /tmp/start&lt;BR /&gt;
touch --date "2013-01-03" /tmp/end&lt;BR /&gt;
find . -type f -newer /tmp/start -not -newer /tmp/end&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 18:11:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162473#M32987</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-12-02T18:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162474#M32988</link>
      <description>&lt;P&gt;in the $SPLUNK_DB/firewall/db I have these files&lt;/P&gt;

&lt;P&gt;drwx------ 3 splunk splunk 8192 Jan 15  2013 db_1357863050_1357725658_118&lt;BR /&gt;
drwx------ 3 splunk splunk 4096 Jan 17  2013 db_1358072144_1357863051_119&lt;BR /&gt;
drwx------ 3 splunk splunk 4096 Jan 18  2013 db_1358267635_1358072147_120&lt;BR /&gt;
drwx------ 3 splunk splunk 8192 Jan 21  2013 db_1358415963_1358267682_121&lt;BR /&gt;
drwx------ 3 splunk splunk 4096 Jan 23  2013 db_1358556654_1358415964_122&lt;BR /&gt;
drwx------ 3 splunk splunk 4096 Jan 24  2013 db_1358773965_1358556655_123&lt;BR /&gt;
drwx------ 3 splunk splunk 8192 Jan 26  2013 db_1358945916_1358773976_12&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:23:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162474#M32988</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2020-09-28T15:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162475#M32989</link>
      <description>&lt;P&gt;COLDDB - not DB&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 18:14:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162475#M32989</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-12-02T18:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162476#M32990</link>
      <description>&lt;P&gt;also just hit me, you have "maxTotalDataSizeMB = 1000000", which is less than 1 TB. Not sure about you, but a years worth of firewall data is more than that. What does &lt;CODE&gt;du -sh $SPLUNK_DB/firewall&lt;/CODE&gt; return?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 18:16:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162476#M32990</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-12-02T18:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162477#M32991</link>
      <description>&lt;P&gt;There are no files in the $SPLUNK_DB/firewall/colddb&lt;/P&gt;

&lt;P&gt;[splunk@Mysystem splunk]$ du -sh firewall/&lt;/P&gt;

&lt;P&gt;978G    firewall/&lt;/P&gt;

&lt;P&gt;I have three indexers with the same size&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 19:07:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162477#M32991</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2013-12-02T19:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162478#M32992</link>
      <description>&lt;P&gt;See my original answer for the answer. You are limiting based on size, not time. Update the conf for the index and it should start storing all the data.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2013 19:25:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162478#M32992</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-12-02T19:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Retention Time Question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162479#M32993</link>
      <description>&lt;P&gt;Kyle,&lt;/P&gt;

&lt;P&gt;You mentoend above that after resoring the buckets I could copy to the db and as long as the bucket ID's don't collide.&lt;/P&gt;

&lt;P&gt;Is that right? or do I need to do a ./splunk rebuild $SPLUNK_HOME/var/lib/splunk/firewall/thaweddb/temp_db_1* &lt;/P&gt;

&lt;P&gt;And then copy reindexed temp folder to $SPLUNK_HOME/var/lib/splunk/firewall/db/db_1*&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:26:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retention-Time-Question/m-p/162479#M32993</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2020-09-28T15:26:57Z</dc:date>
    </item>
  </channel>
</rss>

