Getting Data In

How to configure Splunk to keep _internal data longer than 30 days?

ralphw_SAIC
Path Finder

For some reason _internal is only available for the last 30 days even though it has not reached its max size limit stated in indexes.conf. Is there any way to increase the retention time for _internal and if so where?

0 Karma
1 Solution

anshu
Path Finder

By default, this index is configured to freeze or "archive" data after 30 days. You can customize the "frozenTimePeriodInSecs" attribute for the index. Just replace the value below to the retention period you want in an indexes.conf file in $SPLUNK_HOME/etc/system/local/ or in $SPLUNK_HOME/etc/apps/< app_name > if deploying the configuration via an app.

---indexes.conf---
[_internal]
frozenTimePeriodInSecs = 2592000

View solution in original post

anshu
Path Finder

By default, this index is configured to freeze or "archive" data after 30 days. You can customize the "frozenTimePeriodInSecs" attribute for the index. Just replace the value below to the retention period you want in an indexes.conf file in $SPLUNK_HOME/etc/system/local/ or in $SPLUNK_HOME/etc/apps/< app_name > if deploying the configuration via an app.

---indexes.conf---
[_internal]
frozenTimePeriodInSecs = 2592000

ralphw_SAIC
Path Finder

I have a global of 90days, so just assumed it included _internal.

Thanks for the quick response.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...