Getting Data In

How to increase logs retention period?

islam
Explorer

Hi,

we are asked to increase our retention period of splunk logs to 1 year.

we need to put our data to be searchable for 1 year.

i'm very confused about hot, warm and cold data, are all of them is searchable or cold data is not searchable?

how can we configure this retenion period?

 

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

islam
Explorer

Thank you so much, it's a very useful article.

also i have one question: the values of frozenTimePeriodInSecs and maxTotalDataSizeMB  should be put under every index or just one time at the beginning of indexes.cong file ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If those are same for all your indexes then you can put those on default stanza and if not then you should add those to the individual indexes. 

0 Karma

islam
Explorer

can i put specific period for hot and cold data, like hot data to be 6 months and cold data to be 6 moths also ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

No, only cold period can defined as seconds. Hot/warm is defined by bucket count and/or size of homePath. 
r. Ismo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...