Getting Data In

problems archiving old data

fdesterke
New Member

Hello,

I configured my index in the /etc/system/local/indexes.conf as follows:
[weblogsindex]
homePath = $SPLUNK_DB\weblogsindex\db
coldPath = $SPLUNK_DB\weblogsindex\colddb
thawedPath = $SPLUNK_DB\weblogsindex\thaweddb
frozenTimePeriodInSecs = 47304000

However I don't see any buckets being deleted from the folder, and the disk usage is still increasing.
How can i check what the youngest event in a bucket is, or is there a better way to see if the archiving is working, that would be much appriciated.

Tags (1)
0 Karma

Richfez
SplunkTrust
SplunkTrust

If I may ask a silly question or two - have you confirmed you have data that's older than 1.5 years in that index?

If it's disk space you are trying to control and not actual age of events, perhaps maxTotalDataSizeMB might be a more useful setting? You can find it, as with all other indexes.conf setting, in the documentation:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Admin/Indexesconf
I know that's not an answer to your question, but it might be an answer to your question. 🙂

Also, read carefully the description of frozenTimePeriodInSecs - all the data in the bucket must be older than that age before it'll delete it. By that, I just mean that if you are close - like your oldest data is from 100 days ago and you had frozenTimePeriodInSecs set to 8640000, .... I'd not be worried until you hit at least another few days before it deleted. Is it possible this is the problem?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...