Getting Data In

create index that keeps data by date, not size?

seanlon11
Path Finder

I have many indexes in my environment, which all have a maximum size set. However, we would like to instead keep data in an index according to date. For example: we want to keep all data in an index that is less than 30 days old.

Is this possible?

Thanks,
Sean

Tags (3)
1 Solution

seanlon11
Path Finder

After using some different search times, I have found how to do this by using the frozenTimePeriodInSecs attribute for an index when setting it up in the indexes.conf file.

http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/Setaretirementandarchivingpolicy#Freeze_data...

Simple now that I found it, but maybe this helps someone else out there.

View solution in original post

seanlon11
Path Finder

After using some different search times, I have found how to do this by using the frozenTimePeriodInSecs attribute for an index when setting it up in the indexes.conf file.

http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/Setaretirementandarchivingpolicy#Freeze_data...

Simple now that I found it, but maybe this helps someone else out there.

Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...