Knowledge Management

Increase Cold retention period

saeed
Explorer

Hi,

I would like to increase the cold retention period for index [pa] to 180 days, but when i  get into indexes.conf i only see below configuration there is no frozenTimePeriodInSecs = for index pa

 

# Index for Palo Alto Networks
# This index is required by Splunk_TA_paloalto
[pa]
repFactor = auto
homePath   = volume:hot/pa/db
homePath.maxDataSizeMB = 512000
coldPath   = volume:cold/pa/colddb
coldPath.maxDataSizeMB = 512000
thawedPath = $SPLUNK_DB_THAWED/pa/thaweddb
coldToFrozenDir = $SPLUNK_DB_FROZEN/pa/frozendb
 
 
where can i find the time setting for this index?
 
Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @saeed,

probably your index takes the retention period from the default value (6 years) or from another default definition.

Anyway,

you can add to your index definition also the option:

frozenTimePeriodInSecs = 180

 in this way you define the retention period for that index.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @saeed,

probably your index takes the retention period from the default value (6 years) or from another default definition.

Anyway,

you can add to your index definition also the option:

frozenTimePeriodInSecs = 180

 in this way you define the retention period for that index.

Ciao.

Giuseppe

saeed
Explorer

Thanks a lot 

I will add it and it will be like this:

 
[pa]
repFactor = auto
homePath   = volume:hot/pa/db
homePath.maxDataSizeMB = 512000
coldPath   = volume:cold/pa/colddb
coldPath.maxDataSizeMB = 512000
thawedPath = $SPLUNK_DB_THAWED/pa/thaweddb
coldToFrozenDir = $SPLUNK_DB_FROZEN/pa/frozendb
frozenTimePeriodInSecs = 15552000

 

Correct? 

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @saeed,

if this answer solves your problem, please accept it for the other people of Community.

Otherwise, please tell me what's you problem so I can help you.

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

saeed
Explorer

Thanks a lot @gcusello 

My problem is the current retention period is 52 days and i want to increase the cold storage for Palo Alto index to be searchable for the last 6 months , i only found time setting under [ default ]:

frozenTimePeriodInSecs = 4492800

 i didn't find time period for index [pa]

 

 

 

 

 

 

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @saeed,

in this case, inserting  frozenTimePeriodInSecs in the "pa" index definition (in indexes.conf) you override the default value and you give the value you want only to this index.

Ciao and happy splunking.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...