Getting Data In

automate archive data deletion

jonathanfalconi
Explorer

Hi - I am archiving data to the frozen dir using the frozentimeperiodinseconds which works well. I now want to automate the deletion of this data from my frozen dir after a certain period. I have read somewhere this can be done - can someone point me to documentation which would help.

Tags (3)
0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

There is no automagical management of the frozen buckets. Once they're frozen... you can thaw them (a manual process) or manage the directory yourself (with a script looking at the file dates). The info provided in the doc about the thawing process will give you the bits you need to understand how the buckets are named, organized etc... but they are no longer touched or managed by Splunk once they're frozen, until you thaw them...

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Restorearchiveddata

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...