Getting Data In

create index that keeps data by date, not size?

seanlon11
Path Finder

I have many indexes in my environment, which all have a maximum size set. However, we would like to instead keep data in an index according to date. For example: we want to keep all data in an index that is less than 30 days old.

Is this possible?

Thanks,
Sean

Tags (3)
1 Solution

seanlon11
Path Finder

After using some different search times, I have found how to do this by using the frozenTimePeriodInSecs attribute for an index when setting it up in the indexes.conf file.

http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/Setaretirementandarchivingpolicy#Freeze_data...

Simple now that I found it, but maybe this helps someone else out there.

View solution in original post

seanlon11
Path Finder

After using some different search times, I have found how to do this by using the frozenTimePeriodInSecs attribute for an index when setting it up in the indexes.conf file.

http://docs.splunk.com/Documentation/Splunk/5.0/Indexer/Setaretirementandarchivingpolicy#Freeze_data...

Simple now that I found it, but maybe this helps someone else out there.

Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...