Knowledge Management

data retention for an index how to control archiving policy

New Member

We have several indexes where we have set the maxTotalDataSIzeMB to a specific value is it also possible to configure the frozenTimePeriodInSecs for the same indexes. Can you have both paramters configured for the same index and if so which one takes priority in determining when to delete data is it the size of index or age of the date. For our purpose we are first looking for data to roll off if it exceed 30 days old and as a second check if data is less than 30 days old but index size is greater than 10 GB dta should roll off

0 Karma

Super Champion

Both of these are independent, so either one can trigger a roll.

For the frozenTime setting all events in the db must be older than the setting for the db to roll to frozen, so if the db has many days worth of data you can have more than 30 days stored in the index.

For the size setting, when the index reaches the max size the oldest db will roll.

0 Karma
Get Updates on the Splunk Community!

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...