Security

how long is retention for user logons in Splunk

pratapa
Explorer

Can you please let us know how long is retention for user logons in Splunk.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @pratapa,
if you're speaking of user accesses to Splunk, they are stored in _audit index that, by default, has a six years retention period but it's configurable (like all the indexes retention periods in Splunk) modifying indexes.conf in $SPLUNK_HOME/etc/system/local.

Ciao.
Giuseppe

0 Karma

pratapa
Explorer

Thanks for your reply.

If we want to configure retention period of a logon user, what is the parameter.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @pratapa,
the option is frozenTimePeriodInSecs and you have to add it to the [_audit] stanza in $SPLUNK_HOME/etc/system/local/indexes.conf.
To have more infos, see at https://docs.splunk.com/Documentation/Splunk/8.0.2/Admin/Indexesconf .

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...