Deployment Architecture

Change frozenTimePeriodInSecs of an existing indexes

GaetanVP
Contributor

Hello Splunkers,

I would like to change the value of frozenTimePeriodInSecs for one of my existing indexes.

What should I be careful of ? Juste change the value on my Master Node and push the new bundle to my Indexers ? 

Also since my frozenTimePeriodInSecs will be lower than some of my bucket indexes, those events will be automatically rolled to frozen ? 

Thanks a lot !
GaetanVP

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

As always when changing frozenTimePeriodInSecs, make sure you have the correct value.  Leaving out a digit or doing the maths wrong may result in unintended data deletion.

That said, you have the right idea.  Change the setting on the Cluster Manager and push the bundle.  The indexers will then freeze any buckets that have no data newer than the new frozenTimePeriodInSecs value.

---
If this reply helps you, Karma would be appreciated.

isoutamo
SplunkTrust
SplunkTrust

Hi

one old post to answering your next question “Why I still have older data than….” 😉 It contains also one old but still mostly valid conf presentation.

https://community.splunk.com/t5/Deployment-Architecture/When-will-my-buckets-roll/m-p/579468 

r. Ismo

Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...