Getting Data In

How do I access, use the Splunk retention logs. For Auditing purposes or recover information ?

SamHTexas
Builder

I have learned the the default value is 6 years for  logs retention. So how do I view / use some this data going back say 2-3 years?

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

It will look something like this.  See https://docs.splunk.com/Documentation/Splunk/8.1.3/Search/Specifytimemodifiersinyoursearch#Specify_a...

index=foo earliest=1/15/2021:00:00:00 latest=1/16/2021:00:00:00

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The default retention is ~7 years for user data; retention for internal data is far less - as low as 30 days for _internal.  Assuming you have not changed those settings, you can retrieve older data by specifying an old date in the time picker or by using earliest.

 

index=foo earliest=-3y | ...

 

Of course, this whole discussion (in this and other threads) presumes time is the only retention factor.  If you don't have enough storage for 7 years of data then Splunk will delete the oldest buckets to make room for new ones - and the retention period will be reduced.

---
If this reply helps you, Karma would be appreciated.

SamHTexas
Builder

I thank u sir for your help. So what does this SPL looks like for example you are looking for data om Jan 15, 2021? Thanx

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It will look something like this.  See https://docs.splunk.com/Documentation/Splunk/8.1.3/Search/Specifytimemodifiersinyoursearch#Specify_a...

index=foo earliest=1/15/2021:00:00:00 latest=1/16/2021:00:00:00

 

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...