<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to increase logs retention period? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-increase-logs-retention-period/m-p/509869#M86705</link>
    <description>&lt;P&gt;Thank you so much, it's a very useful article.&lt;/P&gt;&lt;P&gt;also i have one question: the values of&amp;nbsp;&lt;STRONG&gt;frozenTimePeriodInSecs &lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;maxTotalDataSizeMB&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;should be put under every index or just one time at the beginning of indexes.cong file ?&lt;/P&gt;</description>
    <pubDate>Sat, 18 Jul 2020 21:07:35 GMT</pubDate>
    <dc:creator>islam</dc:creator>
    <dc:date>2020-07-18T21:07:35Z</dc:date>
    <item>
      <title>How to increase logs retention period?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-increase-logs-retention-period/m-p/509546#M86674</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;we are asked to increase our retention period of splunk logs to 1 year.&lt;/P&gt;
&lt;P&gt;we need to put our data to be searchable for 1 year.&lt;/P&gt;
&lt;P&gt;i'm very confused about hot, warm and cold data, are all of them is searchable or cold data is not searchable?&lt;/P&gt;
&lt;P&gt;how can we configure this retenion period?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 16:12:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-increase-logs-retention-period/m-p/509546#M86674</guid>
      <dc:creator>islam</dc:creator>
      <dc:date>2020-07-16T16:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase logs retention period?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-increase-logs-retention-period/m-p/509549#M86675</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I hope that this will clarify it.&amp;nbsp;&lt;A href="https://sideviewapps.com/apps/cisco-cdr-reporting-and-analytics/documentation/administrative-concepts/data-retention-policies/?cn-reloaded=1" target="_blank"&gt;https://sideviewapps.com/apps/cisco-cdr-reporting-and-analytics/documentation/administrative-concepts/data-retention-policies/?cn-reloaded=1&lt;/A&gt;&lt;BR /&gt;r. Ismo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 16:36:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-increase-logs-retention-period/m-p/509549#M86675</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-16T16:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase logs retention period?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-increase-logs-retention-period/m-p/509869#M86705</link>
      <description>&lt;P&gt;Thank you so much, it's a very useful article.&lt;/P&gt;&lt;P&gt;also i have one question: the values of&amp;nbsp;&lt;STRONG&gt;frozenTimePeriodInSecs &lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;maxTotalDataSizeMB&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;should be put under every index or just one time at the beginning of indexes.cong file ?&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 21:07:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-increase-logs-retention-period/m-p/509869#M86705</guid>
      <dc:creator>islam</dc:creator>
      <dc:date>2020-07-18T21:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase logs retention period?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-increase-logs-retention-period/m-p/509882#M86708</link>
      <description>&lt;P&gt;If those are same for all your indexes then you can put those on default stanza and if not then you should add those to the individual indexes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jul 2020 10:40:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-increase-logs-retention-period/m-p/509882#M86708</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-19T10:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase logs retention period?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-increase-logs-retention-period/m-p/509993#M86724</link>
      <description>&lt;P&gt;can i put specific period for hot and cold data, like hot data to be 6 months and cold data to be 6 moths also ?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 08:56:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-increase-logs-retention-period/m-p/509993#M86724</guid>
      <dc:creator>islam</dc:creator>
      <dc:date>2020-07-20T08:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to increase logs retention period?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-increase-logs-retention-period/m-p/509997#M86725</link>
      <description>&lt;P&gt;No, only cold period can defined as seconds. Hot/warm is defined by bucket count and/or size of homePath.&amp;nbsp;&lt;BR /&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 09:27:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-increase-logs-retention-period/m-p/509997#M86725</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-20T09:27:57Z</dc:date>
    </item>
  </channel>
</rss>

