Getting Data In

automate archive data deletion

jonathanfalconi
Explorer

Hi - I am archiving data to the frozen dir using the frozentimeperiodinseconds which works well. I now want to automate the deletion of this data from my frozen dir after a certain period. I have read somewhere this can be done - can someone point me to documentation which would help.

Tags (3)
0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

There is no automagical management of the frozen buckets. Once they're frozen... you can thaw them (a manual process) or manage the directory yourself (with a script looking at the file dates). The info provided in the doc about the thawing process will give you the bits you need to understand how the buckets are named, organized etc... but they are no longer touched or managed by Splunk once they're frozen, until you thaw them...

http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Restorearchiveddata

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...