Security

Retention period in GUI?

eroemisch
New Member

Hello,
I am novice at best when it comes to Splunk administration. Running Splunk Enterprise through AWS on a Linux instance, I have one Windows box forwarding over logs. I need to set a retention period of 30 days for the logs then I want them to be deleted.

I keep seeing that this setting would be in indexes.conf, but I am not sure how to access that, can this be done through a GUI or do I have to use the CLI?

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi,
with the current version, you can display retention period using Distributed Monitoring Console, but to set a retention period you can only access the Splunk indexer by CLI and modify indexes.conf.

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi,
with the current version, you can display retention period using Distributed Monitoring Console, but to set a retention period you can only access the Splunk indexer by CLI and modify indexes.conf.

Bye.
Giuseppe

0 Karma

SamHTexas
Builder

Grazie, how do I view this info using Monitoring console with Splunk 8.0 & above?

 

Tags (1)
0 Karma

eroemisch
New Member

Great, thanks for the answer. Is there a default location I should be looking for the indexes.conf? I assume there is a master file that I can set, and if I need to set different times for different servers I can point them to a different conf file?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi eroemisch ,
it depends by your indexes.conf files: you can insert them in each app or create an app dedicated to indexes.
The importanto thing (for me) it's to choose a method and follow it in every app.
I'd avoid to put them in launcher or search apps (usually it happens!) and remeber to put your indexes.conf in local folders and not in default folders.

Bye.
Giuseppe

P.S.: if you're satisfied by this answer, please accept it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...