Deployment Architecture

Change frozenTimePeriodInSecs of an existing indexes

GaetanVP
Contributor

Hello Splunkers,

I would like to change the value of frozenTimePeriodInSecs for one of my existing indexes.

What should I be careful of ? Juste change the value on my Master Node and push the new bundle to my Indexers ? 

Also since my frozenTimePeriodInSecs will be lower than some of my bucket indexes, those events will be automatically rolled to frozen ? 

Thanks a lot !
GaetanVP

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

As always when changing frozenTimePeriodInSecs, make sure you have the correct value.  Leaving out a digit or doing the maths wrong may result in unintended data deletion.

That said, you have the right idea.  Change the setting on the Cluster Manager and push the bundle.  The indexers will then freeze any buckets that have no data newer than the new frozenTimePeriodInSecs value.

---
If this reply helps you, Karma would be appreciated.

isoutamo
SplunkTrust
SplunkTrust

Hi

one old post to answering your next question “Why I still have older data than….” 😉 It contains also one old but still mostly valid conf presentation.

https://community.splunk.com/t5/Deployment-Architecture/When-will-my-buckets-roll/m-p/579468 

r. Ismo

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...