<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does Splunk seem to have more than 90 days of data with our frozenTimePeriodInSecs setting? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-seem-to-have-more-than-90-days-of-data-with-our/m-p/262263#M50342</link>
    <description>&lt;P&gt;Any thoughts, by any chance, on this one?&lt;/P&gt;</description>
    <pubDate>Tue, 24 May 2016 13:27:23 GMT</pubDate>
    <dc:creator>ddrillic</dc:creator>
    <dc:date>2016-05-24T13:27:23Z</dc:date>
    <item>
      <title>Why does Splunk seem to have more than 90 days of data with our frozenTimePeriodInSecs setting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-seem-to-have-more-than-90-days-of-data-with-our/m-p/262262#M50341</link>
      <description>&lt;P&gt;We changed frozenTimePeriodInSecs = 10368000 (120 days from 90 days) for the layer7 index 30 days ago. &lt;/P&gt;

&lt;P&gt;It shows the following:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1386iE65C6455F7C012E0/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;However, when it reached the the three months break of 2/23, it showed &lt;CODE&gt;1,401,173,823 of 1,401,173,823 events matched&lt;/CODE&gt;, but no events kept showing up. We ended up with 2.1 billion events processed. So, it seems as though Splunk has more than 90 days of data, but it stops showing events at the 90 days break.&lt;/P&gt;

&lt;P&gt;On the indexer, under the cold bucket, the oldest directory is of 2/23.&lt;/P&gt;

&lt;P&gt;What can it be?&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 02:21:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-seem-to-have-more-than-90-days-of-data-with-our/m-p/262262#M50341</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-05-24T02:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk seem to have more than 90 days of data with our frozenTimePeriodInSecs setting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-seem-to-have-more-than-90-days-of-data-with-our/m-p/262263#M50342</link>
      <description>&lt;P&gt;Any thoughts, by any chance, on this one?&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 13:27:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-seem-to-have-more-than-90-days-of-data-with-our/m-p/262263#M50342</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-05-24T13:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk seem to have more than 90 days of data with our frozenTimePeriodInSecs setting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-seem-to-have-more-than-90-days-of-data-with-our/m-p/262264#M50343</link>
      <description>&lt;P&gt;You didn't show the time period you picked for your search.  If it was last 90 days then it would only show events for that range.&lt;/P&gt;

&lt;P&gt;As far as the frozenTimePeriodInSecs setting, a bucket will only be frozen if the youngest event in the bucket exceeds that time period.  So there could be buckets with most of their events past 90 days but not all so it will still be in the cold db.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 14:58:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-seem-to-have-more-than-90-days-of-data-with-our/m-p/262264#M50343</guid>
      <dc:creator>sjohnson_splunk</dc:creator>
      <dc:date>2016-05-24T14:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Splunk seem to have more than 90 days of data with our frozenTimePeriodInSecs setting?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-seem-to-have-more-than-90-days-of-data-with-our/m-p/262265#M50344</link>
      <description>&lt;P&gt;Thank you for the help - we "simply" ran out of space for this specific index of 500 GBs. it coincided with the 90 days period which threw us off.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 19:20:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-Splunk-seem-to-have-more-than-90-days-of-data-with-our/m-p/262265#M50344</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-05-24T19:20:49Z</dc:date>
    </item>
  </channel>
</rss>

