Getting Data In

Can we set frozentimePeriodInSecs on a per sourcetype basis?

srinivasup
Explorer

Hi Team,

Is there a way to set frozenTimePeriodInSecs value per sourcetype?
I have the same sourcetype used for multiple sources. Based on our client's requirement, we need to make changes to frozenTimeperiodInSecns based on sourcetype.

Is there a way to make this change?

Thanks

0 Karma

acharlieh
Influencer

frozenTimePeriodinSecs is an indexes.conf configuration. If you need to adjust it per sourcetype, then you need to send the different sourcetypes to different indexes. You could potentially dynamically route the sourcetypes to different indexes as well... See http://docs.splunk.com/Documentation/Splunk/6.4.1/Indexer/Setupmultipleindexes for more info on multiple indexes and this kind of routing.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...