Getting Data In

problems archiving old data

fdesterke
New Member

Hello,

I configured my index in the /etc/system/local/indexes.conf as follows:
[weblogsindex]
homePath = $SPLUNK_DB\weblogsindex\db
coldPath = $SPLUNK_DB\weblogsindex\colddb
thawedPath = $SPLUNK_DB\weblogsindex\thaweddb
frozenTimePeriodInSecs = 47304000

However I don't see any buckets being deleted from the folder, and the disk usage is still increasing.
How can i check what the youngest event in a bucket is, or is there a better way to see if the archiving is working, that would be much appriciated.

Tags (1)
0 Karma

Richfez
SplunkTrust
SplunkTrust

If I may ask a silly question or two - have you confirmed you have data that's older than 1.5 years in that index?

If it's disk space you are trying to control and not actual age of events, perhaps maxTotalDataSizeMB might be a more useful setting? You can find it, as with all other indexes.conf setting, in the documentation:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Admin/Indexesconf
I know that's not an answer to your question, but it might be an answer to your question. 🙂

Also, read carefully the description of frozenTimePeriodInSecs - all the data in the bucket must be older than that age before it'll delete it. By that, I just mean that if you are close - like your oldest data is from 100 days ago and you had frozenTimePeriodInSecs set to 8640000, .... I'd not be worried until you hit at least another few days before it deleted. Is it possible this is the problem?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...