Noticed a new index in our reference Splunk Cloud Victoria stack today - kvcollection_retention_archive
I'm guessing it's related to newer ES functionality on managing KVstore retention?
I also noticed this documentation page show up in the ES 8 doc space, finally explaining the modular input for managing KVstore record retention using managed_configurations.conf (which is still undocumented AFAIK)
https://help.splunk.com/en/splunk-enterprise-security-8/troubleshoot/8.3/troubleshooting/troubleshoo...
Anyone have any information on this new index and the specific role it's playing as far as logging? Why not write KVstore editing events to audit or internal?
The kvcollection_retention_archive index is included in the indexes.conf of the missioncontrol app within ES 8.3 - Its used by the 'mc_kv_store_retention' modular input to store KV Store records that meet the KV Store retention configuration and used as an archive of those records removed, from what I can tell.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing