All Apps and Add-ons

Splunk Add On Web Analytics - Data Retention Policy in KV store

dban2005
New Member

I have recently installed Web Analytics for our ihs logs (sourcetype=access_combined) from LINUX servers. While setting up in Lookup section I had considered Generate user sessions and Generate pages for last 30 days.

1) With the selection Time Period as All time and Show by as "Day", when I had seen data in Traffic Center (Request Count by type), it is showing last 3 months - Why? ( fyi, the retention policy of the relevant index is one year). Can it not go beyond 30 days? Also, I expected the data for only 1 month as I set the lookup for last 30 days, why its showing for 90 days!

2) As understood, the data is first being stored KV store. How can I control the retention policy of for KV store. I do not want the capacity goes beyond it's limit. Also, I can I find out the current size limit and space left for the KV store?

0 Karma

jbjerke_splunk
Splunk Employee
Splunk Employee

Hi guys

The KVstore cleans itself out whenever it add new sessions every 10 minutes in the scheduled search. No need to do anything at all. This process is described in the docs for the app.

j

0 Karma

cabauah
Path Finder

@dban2005 - did you find out how to archive data in kvstore collection and put retention period limit?

0 Karma

dban2005
New Member

I have got the answer as below myself. Please feel free to comment/add to this.

1) The number of days is controlled by Data Model Acceleration set up. After changing the set up to 1 year, I started getting data beyond 90 days

2) Again, the data retention is dependent on the Data Model Acceleration set up. I have set up for 1 year.

0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...