Getting Data In

problems archiving old data

fdesterke
New Member

Hello,

I configured my index in the /etc/system/local/indexes.conf as follows:
[weblogsindex]
homePath = $SPLUNK_DB\weblogsindex\db
coldPath = $SPLUNK_DB\weblogsindex\colddb
thawedPath = $SPLUNK_DB\weblogsindex\thaweddb
frozenTimePeriodInSecs = 47304000

However I don't see any buckets being deleted from the folder, and the disk usage is still increasing.
How can i check what the youngest event in a bucket is, or is there a better way to see if the archiving is working, that would be much appriciated.

Tags (1)
0 Karma

Richfez
SplunkTrust
SplunkTrust

If I may ask a silly question or two - have you confirmed you have data that's older than 1.5 years in that index?

If it's disk space you are trying to control and not actual age of events, perhaps maxTotalDataSizeMB might be a more useful setting? You can find it, as with all other indexes.conf setting, in the documentation:
http://docs.splunk.com/Documentation/Splunk/7.2.1/Admin/Indexesconf
I know that's not an answer to your question, but it might be an answer to your question. 🙂

Also, read carefully the description of frozenTimePeriodInSecs - all the data in the bucket must be older than that age before it'll delete it. By that, I just mean that if you are close - like your oldest data is from 100 days ago and you had frozenTimePeriodInSecs set to 8640000, .... I'd not be worried until you hit at least another few days before it deleted. Is it possible this is the problem?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...