Deployment Architecture

How to keep only 3 months of logs in Splunk

Contributor

I would be creating a backup routine, which keep only 3 months of logs in Splunk. But how can I do to limit the amount of logging for no more than three months old?

Tags (2)
0 Karma

SplunkTrust
SplunkTrust

Here is what you need to do. (replace 30 day with 90 day)

http://answers.splunk.com/answers/57172/how-do-i-set-retention-for-an-index-to-30-days