Monitoring Splunk

Audit index clean up

rranjan2020
New Member

Hello, I am trying to delete data from _audit index. Currently it contains last 6 years data and occupying lot of space. I modified the $SPLUNK_HOME/etc/system/default/indexes.conf and added below under _audit stanza:

 

 

[_audit]
FrozenTimePeriodInSecs = 3153600

 

 

I restarted the splunk after making the changes. But I still see older data under Audit. Can you please help in finding what is wrong here? Do I need to make any additional changes or invoke anything to reflect the changes?

Thanks in advance for your help.

Labels (3)
0 Karma

saravanan90
Contributor

It might be configured in some other apps. Please check the value through btool.

./splunk btool indexes list _audit --debug | grep frozenTimePeriodInSecs

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...