Getting Data In

Splunk Index Retention Policy

ram254481493
Explorer

Hi , I implemented the splunk index retention policy for 6 months and it applies suddenly , i got a lot of free space for the data which is in cold location but my data which is in hot bucket and warm didnt change the size , is their any way that i can roll the data from hot/warm location to cold bucket for a certain period interval such as 6 months ? i applied below stanza for my current 6 month retention and it deleted the data older then 6 months , but i have older data in hot/warm bucket and it didnt delete that data : , i really need to remove the 6 month old data from hot location

[xxxx]
homePath   = $SPLUNK_DB/xxxx/db
coldPath   = $SPLUNK_DB/xxxxxx/colddb
thawedPath = $SPLUNK_DB/xxxx/thaweddb
repFactor  = auto
Added This for new retention policy :
maxHotSpanSecs = 86400
frozenTimePeriodInSecs = 15552000
1 Solution

bpadmanbhachari
Splunk Employee
Splunk Employee

You can try setting below parameter for the index

maxHotSpanSecs = (by default it is 90days for hot buckets to roll to warm.
maxWarmDBCount = (by default it is 300, you can reduce this to make warm buckets to roll to cold soon)

View solution in original post

0 Karma

bpadmanbhachari
Splunk Employee
Splunk Employee

You can try setting below parameter for the index

maxHotSpanSecs = (by default it is 90days for hot buckets to roll to warm.
maxWarmDBCount = (by default it is 300, you can reduce this to make warm buckets to roll to cold soon)

0 Karma

ram254481493
Explorer

Thank you so much but 300 means how long time it take to fill 300 buckets , if i keep 50 buckets means how long it will take to roll the buckets from warm to cold , is any calculations is their ?

0 Karma

bpadmanbhachari
Splunk Employee
Splunk Employee

It depends on your amount of data ingestion. If data ingestion is high, then warm buckets will be filling soon to 50, which rolls to cold.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...