Knowledge Management

data retention for an index how to control archiving policy

splunkjpm
New Member

We have several indexes where we have set the maxTotalDataSIzeMB to a specific value is it also possible to configure the frozenTimePeriodInSecs for the same indexes. Can you have both paramters configured for the same index and if so which one takes priority in determining when to delete data is it the size of index or age of the date. For our purpose we are first looking for data to roll off if it exceed 30 days old and as a second check if data is less than 30 days old but index size is greater than 10 GB dta should roll off

0 Karma

lukejadamec
Super Champion

Both of these are independent, so either one can trigger a roll.

For the frozenTime setting all events in the db must be older than the setting for the db to roll to frozen, so if the db has many days worth of data you can have more than 30 days stored in the index.

For the size setting, when the index reaches the max size the oldest db will roll.

0 Karma
Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of the streaming infrastructure for Splunk APM and Splunk RUM in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...