<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to extend Splunk log retention to forever? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-extend-Splunk-log-retention-to-forever/m-p/597731#M208133</link>
    <description>&lt;P&gt;&lt;SPAN&gt;We have a &amp;nbsp;service for which we have splunk dashboard is in place and right now the dashboard have the limitation that it can populate based on 3 month&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;old data due to log retention policy , but right now there is a business requirement that the dashboard should populate based on forever data.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;so here i want to understand what can be efficient and economical way to extend the log retention to forever in&amp;nbsp;&lt;/SPAN&gt;Splunk.&lt;/P&gt;</description>
    <pubDate>Fri, 13 May 2022 16:12:24 GMT</pubDate>
    <dc:creator>csahoo</dc:creator>
    <dc:date>2022-05-13T16:12:24Z</dc:date>
    <item>
      <title>How to extend Splunk log retention to forever?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extend-Splunk-log-retention-to-forever/m-p/597731#M208133</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have a &amp;nbsp;service for which we have splunk dashboard is in place and right now the dashboard have the limitation that it can populate based on 3 month&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;old data due to log retention policy , but right now there is a business requirement that the dashboard should populate based on forever data.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;so here i want to understand what can be efficient and economical way to extend the log retention to forever in&amp;nbsp;&lt;/SPAN&gt;Splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2022 16:12:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extend-Splunk-log-retention-to-forever/m-p/597731#M208133</guid>
      <dc:creator>csahoo</dc:creator>
      <dc:date>2022-05-13T16:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Extend Splunk log retention to forever</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-extend-Splunk-log-retention-to-forever/m-p/597740#M208138</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245722"&gt;@csahoo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;for my expertience there isn't any requirement from regulations or logic to have a forever retention on your logs!&lt;/P&gt;&lt;P&gt;You should understand if there are regulations requirements that usually are the drivers in retention policies: e.g. in Italy there's a regulation that requires 6 months or retention for system access logs.&lt;/P&gt;&lt;P&gt;About the logs not under a regulation, you could maintain that for three, six or twelve months, more I think that it's completely unuseful.&lt;/P&gt;&lt;P&gt;Eventually, you could maintain some statistics for two or three years, but not full logs.&lt;/P&gt;&lt;P&gt;The reason of this is obviously that logs maintaining requires storage and it cost, especially if you have a great daily volume.&lt;/P&gt;&lt;P&gt;I hope to be useful in my dissertation on maximum systems, at the end, try to have the less quantity of logs as possible&amp;nbsp; to maintain.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2022 08:03:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-extend-Splunk-log-retention-to-forever/m-p/597740#M208138</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-05-13T08:03:33Z</dc:date>
    </item>
  </channel>
</rss>

