Knowledge Management

How to delete data older than 90 days except summary index

dhavamanis
Builder

We have multiple indexes to separate the access / role limit due to data privacy/security (like index1, index2, index3, index4...etc) with cluster setup. Also we want remove data older than 90 days from indexer / indexes. Can you please tell us the best configuration step by step to remove this older data irrespective of indexes with one setup.

Also provide is there any option to exclude the specific index as part of this process. How to keep the summary indexes without truncate for historical data and provide configuration steps.

Many Thanks in Advance!.

1 Solution

somesoni2
Revered Legend

All indexes have property 'frozenTimePeriodInSecs' which defines the duration in seconds for which data will be retained in Splunk. In Indexes.conf file, set the attribute to appropriate value for each index, e.g. 7776000 for indexes you want the data to be available for 90 days, for summary indexes your can set 188697600, 6 years.

See this as well

http://answers.splunk.com/answers/143716/retention-index-or-log-90-days

View solution in original post

somesoni2
Revered Legend

All indexes have property 'frozenTimePeriodInSecs' which defines the duration in seconds for which data will be retained in Splunk. In Indexes.conf file, set the attribute to appropriate value for each index, e.g. 7776000 for indexes you want the data to be available for 90 days, for summary indexes your can set 188697600, 6 years.

See this as well

http://answers.splunk.com/answers/143716/retention-index-or-log-90-days

dhavamanis
Builder

Thank you!

0 Karma
Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...