Getting Data In

How to increase logs retention period?

islam
Explorer

Hi,

we are asked to increase our retention period of splunk logs to 1 year.

we need to put our data to be searchable for 1 year.

i'm very confused about hot, warm and cold data, are all of them is searchable or cold data is not searchable?

how can we configure this retenion period?

 

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

islam
Explorer

Thank you so much, it's a very useful article.

also i have one question: the values of frozenTimePeriodInSecs and maxTotalDataSizeMB  should be put under every index or just one time at the beginning of indexes.cong file ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If those are same for all your indexes then you can put those on default stanza and if not then you should add those to the individual indexes. 

0 Karma

islam
Explorer

can i put specific period for hot and cold data, like hot data to be 6 months and cold data to be 6 moths also ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

No, only cold period can defined as seconds. Hot/warm is defined by bucket count and/or size of homePath. 
r. Ismo

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...