All Apps and Add-ons

Splunk Add On Web Analytics - Data Retention Policy in KV store

dban2005
New Member

I have recently installed Web Analytics for our ihs logs (sourcetype=access_combined) from LINUX servers. While setting up in Lookup section I had considered Generate user sessions and Generate pages for last 30 days.

1) With the selection Time Period as All time and Show by as "Day", when I had seen data in Traffic Center (Request Count by type), it is showing last 3 months - Why? ( fyi, the retention policy of the relevant index is one year). Can it not go beyond 30 days? Also, I expected the data for only 1 month as I set the lookup for last 30 days, why its showing for 90 days!

2) As understood, the data is first being stored KV store. How can I control the retention policy of for KV store. I do not want the capacity goes beyond it's limit. Also, I can I find out the current size limit and space left for the KV store?

0 Karma

jbjerke_splunk
Splunk Employee
Splunk Employee

Hi guys

The KVstore cleans itself out whenever it add new sessions every 10 minutes in the scheduled search. No need to do anything at all. This process is described in the docs for the app.

j

0 Karma

cabauah
Path Finder

@dban2005 - did you find out how to archive data in kvstore collection and put retention period limit?

0 Karma

dban2005
New Member

I have got the answer as below myself. Please feel free to comment/add to this.

1) The number of days is controlled by Data Model Acceleration set up. After changing the set up to 1 year, I started getting data beyond 90 days

2) Again, the data retention is dependent on the Data Model Acceleration set up. I have set up for 1 year.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...