<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Attempting to retire (delete) old data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Attempting-to-retire-delete-old-data/m-p/35758#M178514</link>
    <description>&lt;P&gt;I'm having some trouble getting this to work as well,( I only want to save 6 months back) &lt;BR /&gt;
I've created a indexes.conf and put it in&lt;/P&gt;

&lt;P&gt;/splunk/etc/system/local/indexes.conf&lt;/P&gt;

&lt;P&gt;And the only line in that file is &lt;/P&gt;

&lt;P&gt;frozenTimePeriodInSecs = 15768000.&lt;/P&gt;

&lt;P&gt;I've restarted splunk several times, but nothing happens.&lt;/P&gt;

&lt;P&gt;What would be the easiest way to remove data older than six months and keep it that way based on what I've done?&lt;/P&gt;

&lt;P&gt;Keep in mind I've barely touched Splunk, I just installed it.&lt;/P&gt;

&lt;P&gt;Cheers!&lt;/P&gt;</description>
    <pubDate>Mon, 04 Feb 2013 13:49:38 GMT</pubDate>
    <dc:creator>e2zippo</dc:creator>
    <dc:date>2013-02-04T13:49:38Z</dc:date>
    <item>
      <title>Attempting to retire (delete) old data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Attempting-to-retire-delete-old-data/m-p/35756#M178512</link>
      <description>&lt;P&gt;I would like to trim back on the amount of disk space being used.  We have decided that we would like to keep about 18 months worth of data.  We do not have to retain our data for any legislated period of time.  Last week I added &lt;CODE&gt;frozenTimePeriodInSecs = 46656000&lt;/CODE&gt; to &lt;CODE&gt;/opt/splunk/etc/system/local/indexes.conf&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;I had assumed from the documentation that &lt;CODE&gt;rotatePeriodInSecs = 60&lt;/CODE&gt; in &lt;CODE&gt;/opt/splunk/etc/system/default/indexes.conf&lt;/CODE&gt; would cause the move to frozen (delete) would start almost immediately after a restart.  However, despite a restart, I still have data prior to 18 months ago.&lt;/P&gt;

&lt;P&gt;What am I missing?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2011 13:36:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Attempting-to-retire-delete-old-data/m-p/35756#M178512</guid>
      <dc:creator>RNB</dc:creator>
      <dc:date>2011-06-28T13:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Attempting to retire (delete) old data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Attempting-to-retire-delete-old-data/m-p/35757#M178513</link>
      <description>&lt;P&gt;Splunk will not freeze a bucket until the newest event in the bucket is older than &lt;CODE&gt;frozenTimePeriodInSecs&lt;/CODE&gt;.  Your buckets containing 18+ month old data could have just one event newer than that and it would be enough to keep the whole bucket alive.  You could use the &lt;CODE&gt;dbinspect&lt;/CODE&gt; search command to produce a report on the status of your various buckets.  &lt;A href="http://www.splunk.com/base/Documentation/latest/SearchReference/Dbinspect"&gt;http://www.splunk.com/base/Documentation/latest/SearchReference/Dbinspect&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You'd be looking for buckets where the &lt;CODE&gt;latestTime&lt;/CODE&gt; is more than 46656000 seconds ago - those are the ones that should have rolled off by now.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2011 14:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Attempting-to-retire-delete-old-data/m-p/35757#M178513</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2011-06-28T14:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Attempting to retire (delete) old data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Attempting-to-retire-delete-old-data/m-p/35758#M178514</link>
      <description>&lt;P&gt;I'm having some trouble getting this to work as well,( I only want to save 6 months back) &lt;BR /&gt;
I've created a indexes.conf and put it in&lt;/P&gt;

&lt;P&gt;/splunk/etc/system/local/indexes.conf&lt;/P&gt;

&lt;P&gt;And the only line in that file is &lt;/P&gt;

&lt;P&gt;frozenTimePeriodInSecs = 15768000.&lt;/P&gt;

&lt;P&gt;I've restarted splunk several times, but nothing happens.&lt;/P&gt;

&lt;P&gt;What would be the easiest way to remove data older than six months and keep it that way based on what I've done?&lt;/P&gt;

&lt;P&gt;Keep in mind I've barely touched Splunk, I just installed it.&lt;/P&gt;

&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2013 13:49:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Attempting-to-retire-delete-old-data/m-p/35758#M178514</guid>
      <dc:creator>e2zippo</dc:creator>
      <dc:date>2013-02-04T13:49:38Z</dc:date>
    </item>
  </channel>
</rss>

