Splunk compresses the data by aprox 50% while keeping the data searchable and if moved to frozen (archive) still in a format that you can thaw and make searchable again (re hydrate)
are you asking regarding un compress splunk cold data as it moves from cold to frozen so you can use your enterprise storage technology to dedup it and compress it? if so, what is the savings / compression you anticipate to achieve?
i would not recommend this approach
Hi, Thanks for the reply. Unfortunately storing already compressed data of this volume on storage technology that uses mandatory compression has a massive performance impact on the storage platform. So if it's not possible at all to disable compression on either side, then it's back to the drawing board.