We have multiple indexes to separate the access / role limit due to data privacy/security (like index1, index2, index3, index4...etc) with cluster setup. Also we want remove data older than 90 days from indexer / indexes. Can you please tell us the best configuration step by step to remove this older data irrespective of indexes with one setup.
Also provide is there any option to exclude the specific index as part of this process. How to keep the summary indexes without truncate for historical data and provide configuration steps.
Many Thanks in Advance!.
All indexes have property 'frozenTimePeriodInSecs' which defines the duration in seconds for which data will be retained in Splunk. In Indexes.conf file, set the attribute to appropriate value for each index, e.g. 7776000 for indexes you want the data to be available for 90 days, for summary indexes your can set 188697600, 6 years.
See this as well
http://answers.splunk.com/answers/143716/retention-index-or-log-90-days
All indexes have property 'frozenTimePeriodInSecs' which defines the duration in seconds for which data will be retained in Splunk. In Indexes.conf file, set the attribute to appropriate value for each index, e.g. 7776000 for indexes you want the data to be available for 90 days, for summary indexes your can set 188697600, 6 years.
See this as well
http://answers.splunk.com/answers/143716/retention-index-or-log-90-days
Thank you!