Getting Data In

Data Retention and Warm Buckets

maverick
Splunk Employee
Splunk Employee

My understanding is that a retention policy operates on the events in my cold buckets, meaning that when data grows beyond a certain size I specify for the index, Splunk deletes the oldest data from the cold bucket.

However, if my events never roll from warm to cold bucket, will Splunk still honor my retention policy and delete the data from my warm buckets?

0 Karma

hjwang
Contributor

maybe you can limit the max warm db count with properly adjusting your warm bucket size to enforce it to roll into cold bucket. refer to this discussion

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...