Deployment Architecture

what happens to "|delete"d events when a bucket is thawed?

w199284
Explorer

I have buckets with hidden (deleted) events that are frozen. I want to thaw these buckets. Will I need to re-delete these events?

0 Karma

pruthvikrishnap
Contributor

Hi,

You will have to specify a setting to archive data from frozen, else Splunk will delete all the data.
http://docs.splunk.com/Documentation/Splunk/6.4.0/Indexer/Setaretirementandarchivingpolicy#Archive_d...
http://docs.splunk.com/Documentation/Splunk/6.4.0/Indexer/Automatearchiving

Let me know if this helps.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The OP already has frozen data.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...