Deployment Architecture

what happens to "|delete"d events when a bucket is thawed?

w199284
Explorer

I have buckets with hidden (deleted) events that are frozen. I want to thaw these buckets. Will I need to re-delete these events?

0 Karma

pruthvikrishnap
Contributor

Hi,

You will have to specify a setting to archive data from frozen, else Splunk will delete all the data.
http://docs.splunk.com/Documentation/Splunk/6.4.0/Indexer/Setaretirementandarchivingpolicy#Archive_d...
http://docs.splunk.com/Documentation/Splunk/6.4.0/Indexer/Automatearchiving

Let me know if this helps.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The OP already has frozen data.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...