Getting Data In

problems archiving old data

fdesterke
New Member

Hello,

I configured my index in the /etc/system/local/indexes.conf as follows:
[weblogsindex]
homePath = $SPLUNK_DB\weblogsindex\db
coldPath = $SPLUNK_DB\weblogsindex\colddb
thawedPath = $SPLUNK_DB\weblogsindex\thaweddb
frozenTimePeriodInSecs = 47304000

However I don't see any buckets being deleted from the folder, and the disk usage is still increasing.
How can i check what the youngest event in a bucket is, or is there a better way to see if the archiving is working, that would be much appriciated.

Tags (1)
0 Karma

Richfez
SplunkTrust
SplunkTrust

If I may ask a silly question or two - have you confirmed you have data that's older than 1.5 years in that index?

If it's disk space you are trying to control and not actual age of events, perhaps maxTotalDataSizeMB might be a more useful setting? You can find it, as with all other indexes.conf setting, in the documentation:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Admin/Indexesconf
I know that's not an answer to your question, but it might be an answer to your question. 🙂

Also, read carefully the description of frozenTimePeriodInSecs - all the data in the bucket must be older than that age before it'll delete it. By that, I just mean that if you are close - like your oldest data is from 100 days ago and you had frozenTimePeriodInSecs set to 8640000, .... I'd not be worried until you hit at least another few days before it deleted. Is it possible this is the problem?

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...