Getting Data In

How do I access, use the Splunk retention logs. For Auditing purposes or recover information ?

SamHTexas
Builder

I have learned the the default value is 6 years for  logs retention. So how do I view / use some this data going back say 2-3 years?

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

It will look something like this.  See https://docs.splunk.com/Documentation/Splunk/8.1.3/Search/Specifytimemodifiersinyoursearch#Specify_a...

index=foo earliest=1/15/2021:00:00:00 latest=1/16/2021:00:00:00

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The default retention is ~7 years for user data; retention for internal data is far less - as low as 30 days for _internal.  Assuming you have not changed those settings, you can retrieve older data by specifying an old date in the time picker or by using earliest.

 

index=foo earliest=-3y | ...

 

Of course, this whole discussion (in this and other threads) presumes time is the only retention factor.  If you don't have enough storage for 7 years of data then Splunk will delete the oldest buckets to make room for new ones - and the retention period will be reduced.

---
If this reply helps you, Karma would be appreciated.

SamHTexas
Builder

I thank u sir for your help. So what does this SPL looks like for example you are looking for data om Jan 15, 2021? Thanx

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It will look something like this.  See https://docs.splunk.com/Documentation/Splunk/8.1.3/Search/Specifytimemodifiersinyoursearch#Specify_a...

index=foo earliest=1/15/2021:00:00:00 latest=1/16/2021:00:00:00

 

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...