Getting Data In

Splunk DBConnect and retention

nithin204
Explorer

Hi All,

I am wondering how does the retention works when I am ingesting data which is older than the actual retention period.

For example, I have an index with a rention period of 1yr. I now have a requirement to ingest the data from the database which is older than 1.5yr to Splunk. What happens to the data when I onboard? Will it stay for another 1.5yr or will that become unsearchable soon after ingestion to Splunk.

Thanks in Advance.

0 Karma
1 Solution

sanjeev543
Communicator

Hi Nithin,

Data retention period on Splunk doesn't depends on how old your data in data sources. All it cares about how old is data once it got indexed.

So, in your case you should be able to search your 1.5 years old db data after it's indexed.

View solution in original post

0 Karma

sanjeev543
Communicator

Hi Nithin,

Data retention period on Splunk doesn't depends on how old your data in data sources. All it cares about how old is data once it got indexed.

So, in your case you should be able to search your 1.5 years old db data after it's indexed.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...