Deployment Architecture

Delete Indexed data

eantonio
Path Finder

I want to know when data are moved from Hot to Warm bucket? does it depend on the date it was indexed in Splunk? or does it depend on the size of the Hot Bucket setting? where do i modify this setting?
I saw on the documentation that the maximum size for an index is 500,000MB. Will Splunk only delete data when it reach the 500,000MB limit? or will it still delete the data as long as it reached the Frozen bucket stage? what usually is the time frame before data are deleted from Splunk?

Tags (3)
0 Karma
1 Solution
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...