Getting Data In

Index Data Retention

spl_unker
Explorer

Splunk Query to check what is the Data retention set for hot/warm , cold for each index

0 Karma
1 Solution

nickhills
Ultra Champion

The only duration Splunk uses for data management is the frozen period - ie how long does data remain searchable in Splunk before it is archived or deleted.

The amount of "time" data stays in hot/warm is based on either size, or the number of buckets (not duration)

See the following for info on how to query for frozen durations:
https://answers.splunk.com/answers/476377/how-to-search-and-table-the-retention-time-of-each.html

The best place to check for your index settings is your index definitions.
- on a stand alone indexer, check the indexes.conf on the indexer (you may have to look in multiple apps) $SPLUNK_HOME/etc/apps/appname/[local|default]/indexes.conf
- on an indexer cluster, check the indexes.confs on the cluster master in $SPLUNK_HOME/etc/master-apps/[_cluster|yourapp]/[default|local]/indexes.conf

If my comment helps, please give it a thumbs up!

View solution in original post

0 Karma

nickhills
Ultra Champion

The only duration Splunk uses for data management is the frozen period - ie how long does data remain searchable in Splunk before it is archived or deleted.

The amount of "time" data stays in hot/warm is based on either size, or the number of buckets (not duration)

See the following for info on how to query for frozen durations:
https://answers.splunk.com/answers/476377/how-to-search-and-table-the-retention-time-of-each.html

The best place to check for your index settings is your index definitions.
- on a stand alone indexer, check the indexes.conf on the indexer (you may have to look in multiple apps) $SPLUNK_HOME/etc/apps/appname/[local|default]/indexes.conf
- on an indexer cluster, check the indexes.confs on the cluster master in $SPLUNK_HOME/etc/master-apps/[_cluster|yourapp]/[default|local]/indexes.conf

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

If my answer helped, please consider accepting and/or upvoting so that other memebers of the community can see it was useful.

If my comment helps, please give it a thumbs up!
0 Karma

masonmorales
Influencer

Accepted it on the poster's behalf. Cheers!

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...