Splunk Cloud Platform

Changing the Searchable retention of index- Is there a way to pull data earlier than the 90 day mark?

neerajs_81
Builder

Hello All,   

One of our indexes ( Name: okta ) has a searchable retention period of 90days as shown in the screenshot.

Is there a way to pull data earlier than the 90 day mark ? We want to go back upto last 1 year.    If i change this value to 365 days will it me search thru the old data ( older than 90d ) ? OR is there something more that needs to be done.. ? Thanks in advance

neerajs_81_0-1646811111612.png

 

 

Labels (1)
Tags (2)
0 Karma
1 Solution

SanjayReddy
SplunkTrust
SplunkTrust

Hi @neerajs_81 

you can not  search the older data , over the retention time mentioned , here you can not search for  more than 90 days, but if dymaic data srotage  mentioned than you can archive the data for later usage 

SanjayReddy_0-1646816065203.png
please refer to follwing URL for archiving the data
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Admin/ManageIndexes 

https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataSelfStorage
https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataArchiver 

View solution in original post

SanjayReddy
SplunkTrust
SplunkTrust

Hi @neerajs_81 

you can not  search the older data , over the retention time mentioned , here you can not search for  more than 90 days, but if dymaic data srotage  mentioned than you can archive the data for later usage 

SanjayReddy_0-1646816065203.png
please refer to follwing URL for archiving the data
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Admin/ManageIndexes 

https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataSelfStorage
https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataArchiver 

neerajs_81
Builder

Thanks for responding.   We do not have any Self Storage or Dynamic Storage configured for that index at the moment.  So i assuming, the older data is deleted for good, is that correct ?

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

Hi @neerajs_81 
yes , you are right, data will be deleted post retnetion time

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...