Getting Data In

How can I set up a setting to keep data less than 6 months to stay cold before roll?


I've read all the articles and past questions but I must be missing something. Our requirement is simple 6 months searchable, 6 months frozen. then delete. but seems there is not an easy setting for anything less than cold to say 6months before roll. just seems data sizes?  currently our hot/warm/cold disk space is full and frozen is empty

homePath = volume:primary/ns-switches/db
coldPath = volume:primary/ns-switches/colddb
thawedPath = $SPLUNK_DB/ns-switches/thaweddb
maxTotalDataSizeMB = 512000
maxDataSize = auto_high_volume
coldToFrozenDir = /splunkfrozen/idx1/ns-switches/frozendb
frozenTimePeriodInSecs = 4320000

Labels (1)
0 Karma

Ultra Champion

No errors in logs? Maybe some permission issues?

Your frozen time is pretty low for 6 months - it looks like 50 days or so. It should indeed get rolled to frozen if your buckets are over 50 days old.

0 Karma
Get Updates on the Splunk Community!

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...