Deployment Architecture

how to know and delete old indexed log files in hard disk?

shariinPH
Contributor

Hi all
I want to know what are the old indexed log file and at the same time delete those log files on my hard disk
Pls help me with this.

Thanks

Tags (3)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi shariinPH,

If you haven't set any coldToFrozenScript in your indexes.conf your old events will not be archived http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Automatearchiving

That said, if you're using all default settings for your indexes, Splunk will delete any old events for you.
Check the docs for more details on that http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Setaretirementandarchivingpolicy

Hope that helps ...

cheers, MuS

shariinPH
Contributor

Thanks @MuS !!:)

0 Karma

MuS
SplunkTrust
SplunkTrust

If this answers your question, please accept it - thx 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...