I have a question on Self Storage in Managed Splunk Cloud. I want to have data from a source both searchable in Splunk for 90 days, but also stored in S3 after 1 day. I thought it would be a solution to copy the data from index1 to index2 using a scheduled search (index=index1 | collect index=index2) and set the Searchable time (days) to 1 and let it write the events to S3 using the Self Storage option.
Thanks, kind regards!
I figured this out and if someone would need the answers:
This does not double license costs
The S3 bucket is accessable without Splunk
Kind regards,
I figured this out and if someone would need the answers:
This does not double license costs
The S3 bucket is accessable without Splunk
Kind regards,