Deployment Architecture

Can I manually trigger events in an index to roll to frozen?

andrewtrobec
Motivator

Hello,

I am relatively new to the topic of event rolling between buckets, and I'd like to know how much flexibility I have in choosing what to roll and when. More specifically I would like to trigger an event to roll to frozen (i.e delete) based on field criteria within the event itself. Is this possible?

For example, if I am tracking tasks and I want closed tasks that are older than 6 months to be deleted (not soft delete using delete command), would it be possible to orchestrate some logic that will check both _time and state fields and then roll to frozen?

Thank you and best regards,

Andrew

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Events do not roll between buckets. Entire buckets roll from hot/warm to cold to frozen. Therefore, it is not possible to select individual events to freeze.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Events do not roll between buckets. Entire buckets roll from hot/warm to cold to frozen. Therefore, it is not possible to select individual events to freeze.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...