Getting Data In

automate archive data deletion

jonathanfalconi
Explorer

Hi - I am archiving data to the frozen dir using the frozentimeperiodinseconds which works well. I now want to automate the deletion of this data from my frozen dir after a certain period. I have read somewhere this can be done - can someone point me to documentation which would help.

Tags (3)
0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

There is no automagical management of the frozen buckets. Once they're frozen... you can thaw them (a manual process) or manage the directory yourself (with a script looking at the file dates). The info provided in the doc about the thawing process will give you the bits you need to understand how the buckets are named, organized etc... but they are no longer touched or managed by Splunk once they're frozen, until you thaw them...

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Restorearchiveddata

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...