Deployment Architecture

what happens to "|delete"d events when a bucket is thawed?

w199284
Explorer

I have buckets with hidden (deleted) events that are frozen. I want to thaw these buckets. Will I need to re-delete these events?

0 Karma

pruthvikrishnap
Contributor

Hi,

You will have to specify a setting to archive data from frozen, else Splunk will delete all the data.
http://docs.splunk.com/Documentation/Splunk/6.4.0/Indexer/Setaretirementandarchivingpolicy#Archive_d...
http://docs.splunk.com/Documentation/Splunk/6.4.0/Indexer/Automatearchiving

Let me know if this helps.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The OP already has frozen data.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...