Getting Data In

How to configure Splunk to keep _internal data longer than 30 days?

ralphw_SAIC
Path Finder

For some reason _internal is only available for the last 30 days even though it has not reached its max size limit stated in indexes.conf. Is there any way to increase the retention time for _internal and if so where?

0 Karma
1 Solution

anshu
Path Finder

By default, this index is configured to freeze or "archive" data after 30 days. You can customize the "frozenTimePeriodInSecs" attribute for the index. Just replace the value below to the retention period you want in an indexes.conf file in $SPLUNK_HOME/etc/system/local/ or in $SPLUNK_HOME/etc/apps/< app_name > if deploying the configuration via an app.

---indexes.conf---
[_internal]
frozenTimePeriodInSecs = 2592000

View solution in original post

anshu
Path Finder

By default, this index is configured to freeze or "archive" data after 30 days. You can customize the "frozenTimePeriodInSecs" attribute for the index. Just replace the value below to the retention period you want in an indexes.conf file in $SPLUNK_HOME/etc/system/local/ or in $SPLUNK_HOME/etc/apps/< app_name > if deploying the configuration via an app.

---indexes.conf---
[_internal]
frozenTimePeriodInSecs = 2592000

ralphw_SAIC
Path Finder

I have a global of 90days, so just assumed it included _internal.

Thanks for the quick response.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...