<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to implement a new Retention Policy, and what changes take effect after restarting Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-implement-a-new-Retention-Policy-and-what-changes-take/m-p/286500#M54673</link>
    <description>&lt;P&gt;Yes, the changes are in effect immediately and old data will be frozen (deleted) if necessary to meet the requirements of the new settings.  Your indexers definitely should come with an &lt;CODE&gt;indexes.conf&lt;/CODE&gt; file.&lt;BR /&gt;
Hot buckets cannot be frozen so it will only be warm buckets (cold is frozen already).&lt;BR /&gt;
Keep in mind that this has NOTHING to do with deleting the original files that you are forwarding with &lt;CODE&gt;monitor&lt;/CODE&gt; configurations in &lt;CODE&gt;inputs.conf&lt;/CODE&gt;.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Jun 2016 08:27:00 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2016-06-03T08:27:00Z</dc:date>
    <item>
      <title>How to implement a new Retention Policy, and what changes take effect after restarting Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-implement-a-new-Retention-Policy-and-what-changes-take/m-p/286499#M54672</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I'm currently researching on the use of Retention Policy on Splunk by setting it to only keep data for 6 months. I will most likely be editing &lt;CODE&gt;frozenTimePeriodInSecs&lt;/CODE&gt; attribute in &lt;CODE&gt;indexes.conf&lt;/CODE&gt;. The attribute is currently set to default (which is 6 years I think).&lt;/P&gt;

&lt;P&gt;I have a few questions regarding the implementation of the retention policy and I can't seem to find the answer online. &lt;/P&gt;

&lt;P&gt;May I know after I make the changes to indexes.conf and restart Splunk.&lt;BR /&gt;
 &lt;STRONG&gt;- Does the change take effect immediately? &lt;BR /&gt;
 - What happens to the old data (eg those older than 6 months), will the old data be deleted immediately after restarting? &lt;BR /&gt;
 - Do I have to create the indexes.conf file, or is it already stored inside the server?&lt;BR /&gt;
 - Does this change affect all the buckets, or only those older data in the warm/cold buckets?&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I'm using Splunk to do some automated housekeeping for my log data and I wish to know more about it. &lt;/P&gt;

&lt;P&gt;Any help will be greatly appreciated. Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2016 08:21:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-implement-a-new-Retention-Policy-and-what-changes-take/m-p/286499#M54672</guid>
      <dc:creator>qiaojing</dc:creator>
      <dc:date>2016-06-03T08:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to implement a new Retention Policy, and what changes take effect after restarting Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-implement-a-new-Retention-Policy-and-what-changes-take/m-p/286500#M54673</link>
      <description>&lt;P&gt;Yes, the changes are in effect immediately and old data will be frozen (deleted) if necessary to meet the requirements of the new settings.  Your indexers definitely should come with an &lt;CODE&gt;indexes.conf&lt;/CODE&gt; file.&lt;BR /&gt;
Hot buckets cannot be frozen so it will only be warm buckets (cold is frozen already).&lt;BR /&gt;
Keep in mind that this has NOTHING to do with deleting the original files that you are forwarding with &lt;CODE&gt;monitor&lt;/CODE&gt; configurations in &lt;CODE&gt;inputs.conf&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2016 08:27:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-implement-a-new-Retention-Policy-and-what-changes-take/m-p/286500#M54673</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-06-03T08:27:00Z</dc:date>
    </item>
  </channel>
</rss>

