Deployment Architecture

Splunk archiving setting not working properly

sudhir7
Explorer

I am testing the frozenTimePeriodInSecs setting, I have following default stanza in my indexes.conf file.

[default]
frozenTimePeriodInSecs = 31556736

Still all the indexes are showing data that is older than 7 years.
I was expecting data older than a year to be deleted as I don't have any archive directory setup.
There are two things that could be possible - either the default setting is not being applied to all the indexes or the frozenTimePeriodInSecs setting is not working as expected for me.

Has anyone else faced a similar situation ? Are there any configurational settings I am missing ?

0 Karma

mayurr98
Super Champion

hey, I think you have configured indexes.conf in default?

default is the name of the index?

can you tell where you have configured this setting?

This is found in indexes.conf and is set on a per-index level.

The parameter is called FrozenTimePeriodInSecs and is expressed in seconds. If it does not exist, then the default value of 31556736 is used, which is approximately 6 years.

Read more in the docs,

http://docs.splunk.com/Documentation/Splunk/5.0.3/Indexer/Setaretirementandarchivingpolicy
http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Configureindexstorage

you have to configure this in local/indexes.conf

If default is not the name of the index then the syntax should be

[<your_index_name>]
frozenTimePeriodInSecs = 31556736

let me know if this helps!

0 Karma

sudhir7
Explorer

Hi Mayur,
Thanks for your reply.
I tried adding the line for individual indexes to archive data by adding coldToFrozenDir settings in local/indexes.conf. We have 10TB of data to be archive but the rate of archiving was very very slow around 1GB/day.
Have you tried this in the past ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...