Deployment Architecture

how to know and delete old indexed log files in hard disk?

shariinPH
Contributor

Hi all
I want to know what are the old indexed log file and at the same time delete those log files on my hard disk
Pls help me with this.

Thanks

Tags (3)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi shariinPH,

If you haven't set any coldToFrozenScript in your indexes.conf your old events will not be archived http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Automatearchiving

That said, if you're using all default settings for your indexes, Splunk will delete any old events for you.
Check the docs for more details on that http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Setaretirementandarchivingpolicy

Hope that helps ...

cheers, MuS

shariinPH
Contributor

Thanks @MuS !!:)

0 Karma

MuS
SplunkTrust
SplunkTrust

If this answers your question, please accept it - thx 🙂

0 Karma
Get Updates on the Splunk Community!

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...

Stay Connected: Your Guide to October Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...