Monitoring Splunk

index=_introspection only going back 15 days

toepfer5
Engager

I am trying to look at cpu and mem statistics on my indexers and search heads, but the index only ever goes back 15 days, almost to the hour, but I need to look a a specific date almost a month ago.

Any ideas on why this could be and how can get around it?

Labels (1)
0 Karma

kiran_panchavat
Influencer

When dealing with historical data in Splunk, there are a few factors to consider.

i) Check if your Splunk deployment has custom retention policies configured. You can adjust these policies to retain data for a longer period of time.

I think that you should read at

https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Setaretirementandarchivingpolicy

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check the retention settings on the _introspection index.  By default, it's 14 days.  Change the frozenTimePeriodInSecs setting in indexes.conf to retain data longer.

---
If this reply helps you, Karma would be appreciated.
0 Karma

toepfer5
Engager

Okay, I am assuming that will change the retention for future events, but how can I get the old logs back?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you have backups of the old data, restore them to the thawed folder.  See https://docs.splunk.com/Documentation/Splunk/9.2.0/Indexer/Restorearchiveddata for details.

If you don't have backups then the old data is gone forever.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...