Getting Data In

Index Data Retention

spl_unker
Explorer

Splunk Query to check what is the Data retention set for hot/warm , cold for each index

0 Karma
1 Solution

nickhills
Ultra Champion

The only duration Splunk uses for data management is the frozen period - ie how long does data remain searchable in Splunk before it is archived or deleted.

The amount of "time" data stays in hot/warm is based on either size, or the number of buckets (not duration)

See the following for info on how to query for frozen durations:
https://answers.splunk.com/answers/476377/how-to-search-and-table-the-retention-time-of-each.html

The best place to check for your index settings is your index definitions.
- on a stand alone indexer, check the indexes.conf on the indexer (you may have to look in multiple apps) $SPLUNK_HOME/etc/apps/appname/[local|default]/indexes.conf
- on an indexer cluster, check the indexes.confs on the cluster master in $SPLUNK_HOME/etc/master-apps/[_cluster|yourapp]/[default|local]/indexes.conf

If my comment helps, please give it a thumbs up!

View solution in original post

0 Karma

nickhills
Ultra Champion

The only duration Splunk uses for data management is the frozen period - ie how long does data remain searchable in Splunk before it is archived or deleted.

The amount of "time" data stays in hot/warm is based on either size, or the number of buckets (not duration)

See the following for info on how to query for frozen durations:
https://answers.splunk.com/answers/476377/how-to-search-and-table-the-retention-time-of-each.html

The best place to check for your index settings is your index definitions.
- on a stand alone indexer, check the indexes.conf on the indexer (you may have to look in multiple apps) $SPLUNK_HOME/etc/apps/appname/[local|default]/indexes.conf
- on an indexer cluster, check the indexes.confs on the cluster master in $SPLUNK_HOME/etc/master-apps/[_cluster|yourapp]/[default|local]/indexes.conf

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

If my answer helped, please consider accepting and/or upvoting so that other memebers of the community can see it was useful.

If my comment helps, please give it a thumbs up!
0 Karma

masonmorales
Influencer

Accepted it on the poster's behalf. Cheers!

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...