Getting Data In

Determine how much data splunk is going to 'archive'

tb5821
Communicator

I have a 'frozenTimePeriodInSecs' conf set - how can I tell whats 'aging' out today, tomorrow etc. How much data in GB ??
https://docs.splunk.com/Documentation/Splunk/8.0.0/Indexer/SetARetirementAndArchivingPolicy

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Look in the internal index for bucketmover events.

index=_internal component=BucketMover "freeze"
---
If this reply helps you, Karma would be appreciated.
0 Karma

tb5821
Communicator

hmm that doesn't appear to show the size of whats going to be frozen

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Correct. It also shows what was frozen, not what will be frozen.
To see what will will be frozen, build a query around the dbinspect command. Here's an example I received from someone else:

| dbinspect index=foo
| search NOT state=hot 
| eval frozenTimePeriodInSecs = [| rest /services/data/indexes 
    | search title=foo 
        [| rest /services/server/roles 
        | search role_list="indexer" 
        | fields splunk_server] 
    | dedup frozenTimePeriodInSecs 
    | return $frozenTimePeriodInSecs]
| eval shouldfreeze = endEpoch + frozenTimePeriodInSecs 
| where shouldfreeze < now() 
| convert ctime(shouldfreeze), ctime(*Epoch) 
| table splunk_server bucketId frozenTimePeriodInSecs startEpoch endEpoch shouldfreeze
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...