Deployment Architecture

Splunk index retention based on retention period only not size

Mag2sub
Path Finder

How do we ensure that only say 40 days of data is retained combined across all our buckets hot,warm,cold ....irrespective of incoming data size ..im not interested in 41st day data at any cost ...ie or is it a ballpark calculatioon that can be done based on sizing of these buckets ?

Apreciate pointers

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

FYI, data is not aged out on a per event basis, but on a per bucket basis.

Just be aware that a bucket does not roll to frozen (i.e. is deleted) until the newest event in the bucket is older than the retention limit.

/K

0 Karma

aelliott
Motivator

aelliott
Motivator

you could make maxTotalDataSizeMB a huge number (perhaps the maximum) and use frozenTimePeriodInSecs

Here is a post on this:
http://answers.splunk.com/answers/29126/maxtotaldatasizemb-max-value-or-0

0 Karma

Mag2sub
Path Finder

I guess what is not clear is
is effective delete(provided i dont have freeze dir setup) a combination of frozenTimePeriodInSecs and maxTotalDataSizeMB
or whichever comes first ...

.the idea being from my question if i just dont care my total data size and just need to drop 41st day data irrespective of index total size...i dont see a way in splunk to totally avoid "maxTotalDataSizeMB) and just put frozenTimePeriodInSecs...?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...