Splunk Cloud Platform

Changing the Searchable retention of index- Is there a way to pull data earlier than the 90 day mark?

neerajs_81
Builder

Hello All,   

One of our indexes ( Name: okta ) has a searchable retention period of 90days as shown in the screenshot.

Is there a way to pull data earlier than the 90 day mark ? We want to go back upto last 1 year.    If i change this value to 365 days will it me search thru the old data ( older than 90d ) ? OR is there something more that needs to be done.. ? Thanks in advance

neerajs_81_0-1646811111612.png

 

 

Labels (1)
Tags (2)
0 Karma
1 Solution

SanjayReddy
SplunkTrust
SplunkTrust

Hi @neerajs_81 

you can not  search the older data , over the retention time mentioned , here you can not search for  more than 90 days, but if dymaic data srotage  mentioned than you can archive the data for later usage 

SanjayReddy_0-1646816065203.png
please refer to follwing URL for archiving the data
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Admin/ManageIndexes 

https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataSelfStorage
https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataArchiver 

View solution in original post

SanjayReddy
SplunkTrust
SplunkTrust

Hi @neerajs_81 

you can not  search the older data , over the retention time mentioned , here you can not search for  more than 90 days, but if dymaic data srotage  mentioned than you can archive the data for later usage 

SanjayReddy_0-1646816065203.png
please refer to follwing URL for archiving the data
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Admin/ManageIndexes 

https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataSelfStorage
https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataArchiver 

neerajs_81
Builder

Thanks for responding.   We do not have any Self Storage or Dynamic Storage configured for that index at the moment.  So i assuming, the older data is deleted for good, is that correct ?

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @neerajs_81 
yes , you are right, data will be deleted post retnetion time

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...