Splunk Dev

Splunk Cloud Retention Policy

anandhalagaras1
Communicator

Hi Team,

We have deployed Splunk Cloud in our environment. And by default i believe we have been subscribed for 90 days of retention. i.e. 90 days of data would be available in Splunk for all indexes. This is how it works.

So recently we have increased the retention policy from 90 to 180 days by mid of Jan 2020 so will all the old 180 days of data will be there in Splunk Cloud and it would be searchable? Can you kindly let me know how it works with an example please.

For example:

I have changed the retention policy from 90 to 180 days on Jan 15th 2020 so will it be all the older data would be available in Splunk and it will be searchable. i.e. From July 15th 2019 all data would be available till date for all index and will it be searchable?

Kindly let me know how it works.

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If the retention period is 90 days then anything older than 90 days is deleted. Extending the retention period does not (and can not) undelete old data. The new retention period applies to buckets currently searchable.

For example, if the retention period is 90 days on 14 Jan 20 then the oldest event would be dated 16 Oct 19. If the retention period is changed to 180 days on 15 Jan 20 then the oldest events will still be dated 16 Oct 19, but it will remain searchable until 13 Apr 20.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If the retention period is 90 days then anything older than 90 days is deleted. Extending the retention period does not (and can not) undelete old data. The new retention period applies to buckets currently searchable.

For example, if the retention period is 90 days on 14 Jan 20 then the oldest event would be dated 16 Oct 19. If the retention period is changed to 180 days on 15 Jan 20 then the oldest events will still be dated 16 Oct 19, but it will remain searchable until 13 Apr 20.

---
If this reply helps you, Karma would be appreciated.
0 Karma

anandhalagaras1
Communicator

Thank you for your valuable explanation

0 Karma

anandhalagaras1
Communicator

Kindly help to respond.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...