Getting Data In

How do I access, use the Splunk retention logs. For Auditing purposes or recover information ?

SamHTexas
Builder

I have learned the the default value is 6 years for  logs retention. So how do I view / use some this data going back say 2-3 years?

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

It will look something like this.  See https://docs.splunk.com/Documentation/Splunk/8.1.3/Search/Specifytimemodifiersinyoursearch#Specify_a...

index=foo earliest=1/15/2021:00:00:00 latest=1/16/2021:00:00:00

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The default retention is ~7 years for user data; retention for internal data is far less - as low as 30 days for _internal.  Assuming you have not changed those settings, you can retrieve older data by specifying an old date in the time picker or by using earliest.

 

index=foo earliest=-3y | ...

 

Of course, this whole discussion (in this and other threads) presumes time is the only retention factor.  If you don't have enough storage for 7 years of data then Splunk will delete the oldest buckets to make room for new ones - and the retention period will be reduced.

---
If this reply helps you, Karma would be appreciated.

SamHTexas
Builder

I thank u sir for your help. So what does this SPL looks like for example you are looking for data om Jan 15, 2021? Thanx

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It will look something like this.  See https://docs.splunk.com/Documentation/Splunk/8.1.3/Search/Specifytimemodifiersinyoursearch#Specify_a...

index=foo earliest=1/15/2021:00:00:00 latest=1/16/2021:00:00:00

 

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...