Hello All,
One of our indexes ( Name: okta ) has a searchable retention period of 90days as shown in the screenshot.
Is there a way to pull data earlier than the 90 day mark ? We want to go back upto last 1 year. If i change this value to 365 days will it me search thru the old data ( older than 90d ) ? OR is there something more that needs to be done.. ? Thanks in advance
Hi @neerajs_81
you can not search the older data , over the retention time mentioned , here you can not search for more than 90 days, but if dymaic data srotage mentioned than you can archive the data for later usage
please refer to follwing URL for archiving the data
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Admin/ManageIndexes
https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataSelfStorage
https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataArchiver
Hi @neerajs_81
you can not search the older data , over the retention time mentioned , here you can not search for more than 90 days, but if dymaic data srotage mentioned than you can archive the data for later usage
please refer to follwing URL for archiving the data
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Admin/ManageIndexes
https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataSelfStorage
https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataArchiver
Thanks for responding. We do not have any Self Storage or Dynamic Storage configured for that index at the moment. So i assuming, the older data is deleted for good, is that correct ?
Hi @neerajs_81
yes , you are right, data will be deleted post retnetion time