Getting Data In

Archiving frozen data to another location

johndunlea
Explorer

I want to archive my frozen data to another location which is not on my indexers.

Is the simple way to do this, to set up a shared storage between the machines that the indexers are installed on, and then reference this path within the coldToFrozenDir attribute?

Or are there more complicated Splunk attributes and configurations for this?

1 Solution

jbsplunk
Splunk Employee
Splunk Employee

If you've got an NFS mount point, or something similar to that, and you referenced it with the coldToFrozenDir attribute, then data which meets the criteria to be frozen will be moved to that directory. This is the simple method to achieve this goal.

You do need to carefully consider your data retention policy, but presuming you've got that piece of the action covered, you shouldn't need anything more complicated than coldToFrozenDir.

I tested this configuration last week, and didn't notice anything that seemed strange with regard to the required configuration.

The documentation for this piece of Splunk is here:

http://www.splunk.com/base/Documentation/latest/admin/HowSplunkstoresindexes

View solution in original post

johndunlea
Explorer

Thanks jbssplunk. I thought that this was what could be done, but I was not sure if there would be issues with the shared storage mount.

Thanks!

jbsplunk
Splunk Employee
Splunk Employee

Glad I could help.

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

If you've got an NFS mount point, or something similar to that, and you referenced it with the coldToFrozenDir attribute, then data which meets the criteria to be frozen will be moved to that directory. This is the simple method to achieve this goal.

You do need to carefully consider your data retention policy, but presuming you've got that piece of the action covered, you shouldn't need anything more complicated than coldToFrozenDir.

I tested this configuration last week, and didn't notice anything that seemed strange with regard to the required configuration.

The documentation for this piece of Splunk is here:

http://www.splunk.com/base/Documentation/latest/admin/HowSplunkstoresindexes

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...