Getting Data In

Index Data Retention

spl_unker
Explorer

Splunk Query to check what is the Data retention set for hot/warm , cold for each index

0 Karma
1 Solution

nickhills
Ultra Champion

The only duration Splunk uses for data management is the frozen period - ie how long does data remain searchable in Splunk before it is archived or deleted.

The amount of "time" data stays in hot/warm is based on either size, or the number of buckets (not duration)

See the following for info on how to query for frozen durations:
https://answers.splunk.com/answers/476377/how-to-search-and-table-the-retention-time-of-each.html

The best place to check for your index settings is your index definitions.
- on a stand alone indexer, check the indexes.conf on the indexer (you may have to look in multiple apps) $SPLUNK_HOME/etc/apps/appname/[local|default]/indexes.conf
- on an indexer cluster, check the indexes.confs on the cluster master in $SPLUNK_HOME/etc/master-apps/[_cluster|yourapp]/[default|local]/indexes.conf

If my comment helps, please give it a thumbs up!

View solution in original post

0 Karma

nickhills
Ultra Champion

The only duration Splunk uses for data management is the frozen period - ie how long does data remain searchable in Splunk before it is archived or deleted.

The amount of "time" data stays in hot/warm is based on either size, or the number of buckets (not duration)

See the following for info on how to query for frozen durations:
https://answers.splunk.com/answers/476377/how-to-search-and-table-the-retention-time-of-each.html

The best place to check for your index settings is your index definitions.
- on a stand alone indexer, check the indexes.conf on the indexer (you may have to look in multiple apps) $SPLUNK_HOME/etc/apps/appname/[local|default]/indexes.conf
- on an indexer cluster, check the indexes.confs on the cluster master in $SPLUNK_HOME/etc/master-apps/[_cluster|yourapp]/[default|local]/indexes.conf

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

If my answer helped, please consider accepting and/or upvoting so that other memebers of the community can see it was useful.

If my comment helps, please give it a thumbs up!
0 Karma

masonmorales
Influencer

Accepted it on the poster's behalf. Cheers!

0 Karma
Get Updates on the Splunk Community!

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...

The Visibility Gap: Hybrid Networks and IT Services

The most forward thinking enterprises among us see their network as much more than infrastructure – it's their ...

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...