Deployment Architecture

Cold to Frozen buckets question

paccio84
New Member

Hi @All,
I will explain my situation now:

  • On my Splunk Enterprise (7.2.6) environment I have configured the option ColdToFrozenScript=(script path) and frozenTimePeriodInSecs = 10368000 (120 days).

  • The costumer would like to extend the storage and maintain cold buckets for 3 years (not more 120 days)

  • In the same time they would like to have these frozen buckets/archives created automatically after 120 days

My question is: Is it possible to frozen cold buckets after 120 days and in the same time maintain one searchable copy of them (cold) for 3 years?

Thanks in advance

Regards

Federico

0 Karma
1 Solution

nickhills
Ultra Champion

Once data is frozen it is "offline" and no longer searchable by Splunk.

If I have understood, you should configure splunk with a frozenTimePeriodInSecs which matches the requirements (3 years)
- this will give you searchable data up to 3 years.

Splunk does not manage anything in the frozen path - if you want to archive/move/delete frozen buckets120 days after they are frozen, you will need to script a process (external to splunk) to manage that.

If my comment helps, please give it a thumbs up!

View solution in original post

0 Karma

nickhills
Ultra Champion

Once data is frozen it is "offline" and no longer searchable by Splunk.

If I have understood, you should configure splunk with a frozenTimePeriodInSecs which matches the requirements (3 years)
- this will give you searchable data up to 3 years.

Splunk does not manage anything in the frozen path - if you want to archive/move/delete frozen buckets120 days after they are frozen, you will need to script a process (external to splunk) to manage that.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...