Getting Data In

Is there a default retention period for an index residing in a thawed path and how is it applied?

splunker12er
Motivator

After I restore the archived data in thawed path and rebuild the index - Splunk recognizes the data.

What is the life-time of the data residing in the thawed path? Is there any default retention period for this?

By default splunk data rotation (hotdb->warmdb->colddb(deleted after 6 years))
Now, I place the buckets inside a thawed path and rebuilt it. How is that default policy is applied here?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If the bucket was frozen due to age, retention would immediately re-freeze it. If it was frozen due to index size, that would also immediately re-freeze it.

As a result, thawed buckets are outside the scope of both retention time and size restrictions for that index, the Splunk admins handle these themselves.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...