For some reason _internal is only available for the last 30 days even though it has not reached its max size limit stated in indexes.conf. Is there any way to increase the retention time for _internal and if so where?
By default, this index is configured to freeze or "archive" data after 30 days. You can customize the "frozenTimePeriodInSecs" attribute for the index. Just replace the value below to the retention period you want in an indexes.conf file in $SPLUNK_HOME/etc/system/local/ or in $SPLUNK_HOME/etc/apps/< app_name > if deploying the configuration via an app.
---indexes.conf---
[_internal]
frozenTimePeriodInSecs = 2592000
By default, this index is configured to freeze or "archive" data after 30 days. You can customize the "frozenTimePeriodInSecs" attribute for the index. Just replace the value below to the retention period you want in an indexes.conf file in $SPLUNK_HOME/etc/system/local/ or in $SPLUNK_HOME/etc/apps/< app_name > if deploying the configuration via an app.
---indexes.conf---
[_internal]
frozenTimePeriodInSecs = 2592000
I have a global of 90days, so just assumed it included _internal.
Thanks for the quick response.