I have learned the the default value is 6 years for logs retention. So how do I view / use some this data going back say 2-3 years?
It will look something like this. See https://docs.splunk.com/Documentation/Splunk/8.1.3/Search/Specifytimemodifiersinyoursearch#Specify_a...
index=foo earliest=1/15/2021:00:00:00 latest=1/16/2021:00:00:00
The default retention is ~7 years for user data; retention for internal data is far less - as low as 30 days for _internal. Assuming you have not changed those settings, you can retrieve older data by specifying an old date in the time picker or by using earliest.
index=foo earliest=-3y | ...
Of course, this whole discussion (in this and other threads) presumes time is the only retention factor. If you don't have enough storage for 7 years of data then Splunk will delete the oldest buckets to make room for new ones - and the retention period will be reduced.
I thank u sir for your help. So what does this SPL looks like for example you are looking for data om Jan 15, 2021? Thanx
It will look something like this. See https://docs.splunk.com/Documentation/Splunk/8.1.3/Search/Specifytimemodifiersinyoursearch#Specify_a...
index=foo earliest=1/15/2021:00:00:00 latest=1/16/2021:00:00:00