Splunk Dev

Indexed counts dropping

stevennoble
Explorer

I appear to be de-indexing data because my global count sometimes goes down and certain count queries drop. I assume there is data expiry settings somewhere but I'm not sure where to look.

Tags (1)
0 Karma

lukejadamec
Super Champion

Read this document. It will explain the settings. You can select your Splunk version in the upper right:

http://docs.splunk.com/Documentation/Splunk/6.0/Indexer/Setaretirementandarchivingpolicy

0 Karma
Get Updates on the Splunk Community!

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...

Getting Started with Splunk Artificial Intelligence, Insights for Nonprofits, and ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...