Getting Data In

automate archive data deletion

jonathanfalconi
Explorer

Hi - I am archiving data to the frozen dir using the frozentimeperiodinseconds which works well. I now want to automate the deletion of this data from my frozen dir after a certain period. I have read somewhere this can be done - can someone point me to documentation which would help.

Tags (3)
0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

There is no automagical management of the frozen buckets. Once they're frozen... you can thaw them (a manual process) or manage the directory yourself (with a script looking at the file dates). The info provided in the doc about the thawing process will give you the bits you need to understand how the buckets are named, organized etc... but they are no longer touched or managed by Splunk once they're frozen, until you thaw them...

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Restorearchiveddata

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...