Getting Data In

Frozen Time Period in seconds based on Sourcetype

Dark_Ichigo
Builder

Why cant I choose a source type of an index instead of the whole index to move my index data from the specific source type chosen to the frozen bucket?

I dont want to move all of the index, I just want to chose a specific source type within that index to be moved to a cold or frozen bucket at a given specified time.

dwaddle
SplunkTrust
SplunkTrust

The smallest index unit is a bucket. Sourcetypes are really just a "descriptive marker" on events within a bucket. You cannot choose different expiry periods for different sourcetypes in a bucket because Splunk's architecture is just not designed that way.

You can always file an enhancement request asking for this type of functionality. But, it breaks some pretty foundational tenets of how Splunk indexes work.

yannK
Splunk Employee
Splunk Employee

Segregate your data in multiple indexes based on the sourcetype. And then specify different retentions per index.

Dark_Ichigo
Builder

What do you reckon would be an alternative then in this case, how can I be able to specify this with Splunks current functionalists..

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...