Monitoring Splunk

index=_introspection only going back 15 days

toepfer5
Engager

I am trying to look at cpu and mem statistics on my indexers and search heads, but the index only ever goes back 15 days, almost to the hour, but I need to look a a specific date almost a month ago.

Any ideas on why this could be and how can get around it?

Labels (1)
0 Karma

kiran_panchavat
Influencer

When dealing with historical data in Splunk, there are a few factors to consider.

i) Check if your Splunk deployment has custom retention policies configured. You can adjust these policies to retain data for a longer period of time.

I think that you should read at

https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setaretirementandarchivingpolicy

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check the retention settings on the _introspection index.  By default, it's 14 days.  Change the frozenTimePeriodInSecs setting in indexes.conf to retain data longer.

---
If this reply helps you, Karma would be appreciated.
0 Karma

toepfer5
Engager

Okay, I am assuming that will change the retention for future events, but how can I get the old logs back?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you have backups of the old data, restore them to the thawed folder.  See https://docs.splunk.com/Documentation/Splunk/9.2.0/Indexer/Restorearchiveddata for details.

If you don't have backups then the old data is gone forever.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...