Splunk Cloud Platform

Changing the Searchable retention of index- Is there a way to pull data earlier than the 90 day mark?

neerajs_81
Builder

Hello All,   

One of our indexes ( Name: okta ) has a searchable retention period of 90days as shown in the screenshot.

Is there a way to pull data earlier than the 90 day mark ? We want to go back upto last 1 year.    If i change this value to 365 days will it me search thru the old data ( older than 90d ) ? OR is there something more that needs to be done.. ? Thanks in advance

neerajs_81_0-1646811111612.png

 

 

Labels (1)
Tags (2)
0 Karma
1 Solution

SanjayReddy
SplunkTrust
SplunkTrust

Hi @neerajs_81 

you can not  search the older data , over the retention time mentioned , here you can not search for  more than 90 days, but if dymaic data srotage  mentioned than you can archive the data for later usage 

SanjayReddy_0-1646816065203.png
please refer to follwing URL for archiving the data
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Admin/ManageIndexes 

https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataSelfStorage
https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataArchiver 

View solution in original post

SanjayReddy
SplunkTrust
SplunkTrust

Hi @neerajs_81 

you can not  search the older data , over the retention time mentioned , here you can not search for  more than 90 days, but if dymaic data srotage  mentioned than you can archive the data for later usage 

SanjayReddy_0-1646816065203.png
please refer to follwing URL for archiving the data
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Admin/ManageIndexes 

https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataSelfStorage
https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataArchiver 

neerajs_81
Builder

Thanks for responding.   We do not have any Self Storage or Dynamic Storage configured for that index at the moment.  So i assuming, the older data is deleted for good, is that correct ?

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @neerajs_81 
yes , you are right, data will be deleted post retnetion time

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...