Deployment Architecture

Is there Splunk support for remaining 90 day data retention?

anandhalagaras1
Contributor

We have Splunk Cloud deployed in our environment and we have set the default data retention that is 90 days.

So for example if I require the data for the last 180 days I can able to search the logs in Splunk cloud for the last 90 days, and for the remaining 90 days- will the data be archived anywhere at the backend by Splunk support?

So if we require those logs will Splunk support be able to provide the same via offline?

And usually, we want to know whether Splunk support archives our old data which is more than 90 days? Since we require those data for legal purpose whether they can able to provide the same.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

By default, Splunk Cloud stores data for 90 days. Anything older than that is deleted and cannot be restored. If you need longer retention periods, you need to contact your Splunk sales rep and buy additional storage.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...