Getting Data In

How to increase logs retention period?

islam
Explorer

Hi,

we are asked to increase our retention period of splunk logs to 1 year.

we need to put our data to be searchable for 1 year.

i'm very confused about hot, warm and cold data, are all of them is searchable or cold data is not searchable?

how can we configure this retenion period?

 

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

islam
Explorer

Thank you so much, it's a very useful article.

also i have one question: the values of frozenTimePeriodInSecs and maxTotalDataSizeMB  should be put under every index or just one time at the beginning of indexes.cong file ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If those are same for all your indexes then you can put those on default stanza and if not then you should add those to the individual indexes. 

0 Karma

islam
Explorer

can i put specific period for hot and cold data, like hot data to be 6 months and cold data to be 6 moths also ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

No, only cold period can defined as seconds. Hot/warm is defined by bucket count and/or size of homePath. 
r. Ismo

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...