Getting Data In

Query - to get actual rentention period set & remaining days left for rentention

splunker12er
Motivator

Splunk query to get ,

Actual retention set for an index
Remaining days left to meet retention date
Current Index_size

0 Karma

datasearchninja
Communicator

The retention set for an index on each indexer is available at this rest endpoint:

| rest /services/data/indexes/INDEXNAME

dbinspect can look at each bucket and show the endEpoch, rawsize, and size on disk for each bucket

| dbinspect index=INDEXNAME 

The 2 could be put together to print out the expiry date with something like this. (This example for the os index)

| dbinspect index=os | table splunk_server bucketId endEpoch rawSize sizeOnDiskMB | join splunk_server [rest /services/data/indexes/os | fields splunk_server frozenTimePeriodInSecs] | eval frozentime=endEpoch+frozenTimePeriodInSecs | sort frozentime | convert TIMEFORMAT="%Y-%m-%d %H:%M:%S" ctime(frozentime) as frozentime

The total index size is also at the index rest endpoint, or you could sum the bucket counts.

0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...