Splunk Cloud Platform

Copy data from an index to Self Storage

willemjongeneel
Communicator

Hello,

I have a question on Self Storage in Managed Splunk Cloud. I want to have data from a source both searchable in Splunk for 90 days, but also stored in S3 after 1 day. I thought it would be a solution to copy the data from index1 to index2 using a scheduled search (index=index1 | collect index=index2) and set the Searchable time (days) to 1 and let it write the events to S3 using the Self Storage option.

  • Does this double the license costs?
  • Is the data in this S3 bucket accessable without Splunk for DWH purposes?

Thanks, kind regards!
Willem

Tags (2)
0 Karma
1 Solution

willemjongeneel
Communicator

Hello,

I figured this out and if someone would need the answers:

This does not double license costs
The S3 bucket is accessable without Splunk

Kind regards,
Willem

View solution in original post

0 Karma

willemjongeneel
Communicator

Hello,

I figured this out and if someone would need the answers:

This does not double license costs
The S3 bucket is accessable without Splunk

Kind regards,
Willem

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...