Installation

ignore old logs control from indexer cluster

sramiz
Path Finder

Hello,

We are running 3 SH and 3 indexers cluster.  wondering how can we restrict indexers to ignore logs older than 30 days? I understand that it can be managed on UF inputs.conf by using ignoreOlderThan but is there a way to control this from indexers cluster level settings?

Note: sorry for a basic question but I am a beginner in splunking

thanks

SR

 

Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi, @sramiz,

You can achieve this by index retention setting to 30 days.

[index_name]
frozenTimePeriodInSecs = 2592000

 

If this reply helps you, an upvote is appreciated.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sramiz
Path Finder

hi @scelikok Thanks for your reply but its not about deleting index or retention period. I want to know if there is a way for UF to ignore any logs that are older than 30 days and if this setting can in place from indexer cluster not in UF's inputs.conf.

thanks again

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...