<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index time based retention - based on indexed time or event time? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/51397#M9860</link>
    <description>&lt;P&gt;Indexed data has the original Timestamp of the incoming events into Splunk.&lt;BR /&gt;
SO, every events are synchronized with event time and not the indexed time. &lt;BR /&gt;
Later ,data will be moved from Hot-&amp;gt;Warm-&amp;gt; Cold.-&amp;gt;Frozen(based on indexes.conf settings)&lt;BR /&gt;
When we Search for historical data , we need to restore the indexed data to thawed path , and by renaming the indexes (you might read the restore archived data in Splunk) ,we could able to see the historical events with historical Timestamp.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jun 2013 14:36:30 GMT</pubDate>
    <dc:creator>chimbudp</dc:creator>
    <dc:date>2013-06-25T14:36:30Z</dc:date>
    <item>
      <title>Index time based retention - based on indexed time or event time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/51395#M9858</link>
      <description>&lt;P&gt;This information is probably located in one of the docs but didn't find it in anything I've read just now. Under normal circumstances current data rolls in and rolls out based on any number of parameters such as frozenTimePeriodInSecs. What happens when you ingest a bunch of historical data though and how does that impact retention? If the retention is strictly sized based it is one thing but time based seems to be another. My gut says this would be based on indexed time but not sure how historical data and timestamps play into bucket creation.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2013 18:20:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/51395#M9858</guid>
      <dc:creator>Runals</dc:creator>
      <dc:date>2013-05-30T18:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Index time based retention - based on indexed time or event time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/51396#M9859</link>
      <description>&lt;P&gt;It's based upon the event time.&lt;/P&gt;

&lt;P&gt;A bucket (the constituent of an index, (read more &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/Indexer/HowSplunkstoresindexes"&gt;here&lt;/A&gt;) spans a range of time. This range is set by the event time of the events in that bucket. A bucket is a candidate for rotation (this includes hot to warm, warm to cold, and cold to frozen) when it is the oldest bucket "in scope"(*). Oldest by this definition is based upon the &lt;EM&gt;newest&lt;/EM&gt; time in the index. So a bucket can contain events from 2010, and then have a single event from June 21 2013, and it won't be a candidate for &lt;EM&gt;time based&lt;/EM&gt; rules until frozenTimePeriodInSecs &lt;EM&gt;after&lt;/EM&gt; June 21, 2013.&lt;/P&gt;

&lt;P&gt;Note also that the most restrictive rule applies, so if an index is nowhere near full, but the time-based rule says it's time to go, then the bucket will be frozen (consider the _internal index; it has a max size of 500GB, but a retention time period of only 28 days).&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Scope can be an entire volume, spanning multiple indexes (with volume:foo directives), or a single index, or an bucket state within an index, such as "warm buckets".&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 25 Jun 2013 14:27:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/51396#M9859</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-06-25T14:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Index time based retention - based on indexed time or event time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/51397#M9860</link>
      <description>&lt;P&gt;Indexed data has the original Timestamp of the incoming events into Splunk.&lt;BR /&gt;
SO, every events are synchronized with event time and not the indexed time. &lt;BR /&gt;
Later ,data will be moved from Hot-&amp;gt;Warm-&amp;gt; Cold.-&amp;gt;Frozen(based on indexes.conf settings)&lt;BR /&gt;
When we Search for historical data , we need to restore the indexed data to thawed path , and by renaming the indexes (you might read the restore archived data in Splunk) ,we could able to see the historical events with historical Timestamp.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 14:36:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/51397#M9860</guid>
      <dc:creator>chimbudp</dc:creator>
      <dc:date>2013-06-25T14:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Index time based retention - based on indexed time or event time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/51398#M9861</link>
      <description>&lt;P&gt;As a follow-up to this, note that thawed data lives outside of any retention policy whatsoever. The buckets therein must be managed manually.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2013 16:08:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/51398#M9861</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-06-25T16:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: Index time based retention - based on indexed time or event time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/51399#M9862</link>
      <description>&lt;P&gt;What happens when the old data is in hotbucket? Does this &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;"This range is set by the event time&lt;BR /&gt;
of the events in that bucket."&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;still applied here ? The folder name does not it show this for hot bucket like it is mentioned for the warm buckets.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2018 08:56:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/51399#M9862</guid>
      <dc:creator>immortalraghava</dc:creator>
      <dc:date>2018-01-29T08:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Index time based retention - based on indexed time or event time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/748730#M118968</link>
      <description>&lt;P&gt;Data retention is not based on _time, its actually based on _indextime and max size set for example, if I index below sample data now,&lt;BR /&gt;&lt;BR /&gt;2020-03-02 12:23:23 blah blah&lt;BR /&gt;Retention time: 6months&lt;/P&gt;&lt;P&gt;Maxsize: 100GB&lt;/P&gt;&lt;P&gt;then the _time of the event will be&amp;nbsp;2020-03-02 12:23:23 but _indextime will be 2025-06-25 HH:MM:SS&lt;BR /&gt;&lt;BR /&gt;so this data will not get deleted immediately since _time of this event is 5 years old.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 16:23:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/748730#M118968</guid>
      <dc:creator>apujar</dc:creator>
      <dc:date>2025-06-25T16:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: Index time based retention - based on indexed time or event time?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/748747#M118976</link>
      <description>&lt;P&gt;Firstly, a golden shovel. This is a very very old thread.&lt;/P&gt;&lt;P&gt;Secondly, you are mistaken. While the event will not get "immediately deleted" but for a completely different reason. There are several factors here:&lt;/P&gt;&lt;P&gt;- events are not handled on their own but by buckets&lt;/P&gt;&lt;P&gt;- hot buckets do not roll to frozen directly&lt;/P&gt;&lt;P&gt;- "unusual" events (too far in the past or "from the future") are indexed in quarantine buckets which might get rolled completely differently than your normal buckets.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 19:11:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-time-based-retention-based-on-indexed-time-or-event-time/m-p/748747#M118976</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-06-25T19:11:34Z</dc:date>
    </item>
  </channel>
</rss>

