Deployment Architecture

what is thawed directory and when does data move to thawed directory?

SoknySplunk
Loves-to-Learn Lots

After red splunk document, i still confuse thawed directory and frozen. i would like to ask you,
what is thawed directory? when does data move to thawed directory?

Tags (1)
0 Karma

adonio
Ultra Champion

hello there,

frozen directory does not exist unless you define it.
splunk by default will delete / remove buckets from cold as they either reach the time or size thresholds defined (whatever comes first)
if you set the frozen location, data (buckets) in this location are not readable.
thawed directory is a place to put data that you would like to recover after it was frozen.
buckets in the thawed directory are readable by splunk.

hope it clarifies it.

further reading:
https://docs.splunk.com/Documentation/Splunk/7.0.2/Indexer/HowSplunkstoresindexes
https://docs.splunk.com/Documentation/Splunk/7.0.2/Indexer/Configureindexstorage
https://docs.splunk.com/Documentation/Splunk/7.0.2/Indexer/Restorearchiveddata

0 Karma

HiroshiSatoh
Champion

Do you mean bucket rotation of index?
The default frozen setting is deleted. Settings are necessary to archive.

http://wiki.splunk.com/Deploy:BucketRotationAndRetention

0 Karma
Get Updates on the Splunk Community!

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...