Is there a way to audit who has modified the searchable retention period for the various indexes in Splunk cloud

Loves-to-Learn Everything

We found that the searchable events for our  wineventlog only goes back about 4 months but the searchable retention is set to 2 years 364 days (which is a total of 3 years). Splunk has said that the most likely scenario is that someone has changed the retention period recently.  We would like to find out who has modified the searchable retention period.

I have looked in the audit logs but that also only goes back about 5 months and have not found anything useful. I have also googled and have not found any solutions. Would appreciate any help. Thank you.

Labels (1)
0 Karma



another option is that you have lack of disk space and for that reason splunk has frozen those events before retention time has fulfil.

If you haven't have audit logs and haven't set any VCS into use there probably haven't any way to get this info. 

For future use you could check this:

As this is Splunk Cloud, have you bought additional disk capacity over standard 90 days?

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...