Getting Data In

Determine how much data splunk is going to 'archive'

tb5821
Communicator

I have a 'frozenTimePeriodInSecs' conf set - how can I tell whats 'aging' out today, tomorrow etc. How much data in GB ??
https://docs.splunk.com/Documentation/Splunk/8.0.0/Indexer/SetARetirementAndArchivingPolicy

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Look in the internal index for bucketmover events.

index=_internal component=BucketMover "freeze"
---
If this reply helps you, Karma would be appreciated.
0 Karma

tb5821
Communicator

hmm that doesn't appear to show the size of whats going to be frozen

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Correct. It also shows what was frozen, not what will be frozen.
To see what will will be frozen, build a query around the dbinspect command. Here's an example I received from someone else:

| dbinspect index=foo
| search NOT state=hot 
| eval frozenTimePeriodInSecs = [| rest /services/data/indexes 
    | search title=foo 
        [| rest /services/server/roles 
        | search role_list="indexer" 
        | fields splunk_server] 
    | dedup frozenTimePeriodInSecs 
    | return $frozenTimePeriodInSecs]
| eval shouldfreeze = endEpoch + frozenTimePeriodInSecs 
| where shouldfreeze < now() 
| convert ctime(shouldfreeze), ctime(*Epoch) 
| table splunk_server bucketId frozenTimePeriodInSecs startEpoch endEpoch shouldfreeze
---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...