Deployment Architecture

what happens to "|delete"d events when a bucket is thawed?

w199284
Explorer

I have buckets with hidden (deleted) events that are frozen. I want to thaw these buckets. Will I need to re-delete these events?

0 Karma

pruthvikrishnap
Contributor

Hi,

You will have to specify a setting to archive data from frozen, else Splunk will delete all the data.
http://docs.splunk.com/Documentation/Splunk/6.4.0/Indexer/Setaretirementandarchivingpolicy#Archive_d...
http://docs.splunk.com/Documentation/Splunk/6.4.0/Indexer/Automatearchiving

Let me know if this helps.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The OP already has frozen data.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...