Getting Data In

What timestamp is used to count the seconds to satisfy the frozen bucket time?

ankithreddy777
Contributor

On what time basis Splunk data moves to frozen after it satisfied frozenTimePeriosdinSecs.

Index Time of event OR Timestamp of the event ?

Because I have seen events still not deleted who's timestamp is older than given frozenTimePeriosdinSecs time.

0 Karma

hgrow
Communicator

hi there,

without answering your question .. splunk does not rotate per event but per bucket. so it can happen that very old AND new events get mixed together in one bucket and this specific bucket is only allowed ro rotate if all events matches your frozenTime-parameter so your bucket with old and new data is basicly not allowed to rotate. this can happen if your sourcetypes time extraction is off or you just get weird data indexed somehow or many many more reasons.

There is a field called _bkt. you can check the time period for that specific bucket that holds older events than your frozentimeperiod.
greetings

0 Karma

hgrow
Communicator
0 Karma

somesoni2
Revered Legend

Splunk does data retention based on timestamp of event (_time). The retention period that you specify in frozenTimePeriosdinSecs is basically the "minimum retention" that you'll see for your data, not the cutoff. The reason for this is that data retention is done for the buckets, not individual events. The data is stored in buckets where a bucket can have data for varied range of timestamp. A bucket (cold) is only frozen if all it's events are older than retention period, so even though a bucket contains some data older than frozenTimePeriodInSecs, there may be some which are not and thus the bucket stays.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...