Deployment Architecture

Has anyone used coldToFrozenScript in indexes.conf for archiving in an indexer clustering environment?

sbhat13
New Member

We need to do indexer archiving. We have a clustered environment with 4 Search Heads and 4 indexers each. Can anyone suggest if you have ever tried the option of using coldToFrozenScript in the indexes.conf? If yes, let me know what details have to be mentioned there and how can it be used.

Thanks,
Soumya

0 Karma

kpawar_splunk
Splunk Employee
Splunk Employee

You can find information about splunk indexer archiving here : http://docs.splunk.com/Documentation/Splunk/6.4.2/Indexer/Automatearchiving
Indexes.conf settings related to coldToFrozenScript are mentioned here : http://docs.splunk.com/Documentation/Splunk/6.4.2/Admin/Indexesconf

0 Karma

sbhat13
New Member

I have referred the docs and noticed that the sample script is available for this in the Splunk Enterprise product.But I am not sure of what all parameters need to be added/changed in this script for it to work in our case.We have a linux server hosting splunk in clustered environment.Some simple example would be easier to understand.
cat /opt/splunk/bin/coldToFrozenExample.py

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...