Splunk Dev

Splunk Trustar

sunnykhatik1019
New Member

Subject: Trustar API : Data Retention Policy Inquiry

Dear Splunk Community,

We are currently utilizing your search_indicators API, as documented here: https://docs.trustar.co/api/v13/indicators/search_indicators.html.

While we understand that the API supports a maximum time range of 1 year per query, we require clarification on the overall data retention policy for indicators. I just want to know the total historical period for which indicator data is stored and retrievable via this API, regardless of the single query window limit?

Your insight into this would be greatly appreciated for our data strategy.

TruSTAR 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @sunnykhatik1019 

Other than the single query limit you mentioned, there are no publicly documented historic retention details regarding TruStar. I'd recommend reaching out to support and/or your Splunk account team who may be able to dig into this a little further for you and get proper confirmation/clarification.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

sunnykhatik1019
New Member

Hi @livehybrid ,
Yes, you've hit on my exact point.

I'm trying to determine the best way to contact support – specifically, if their assistance is limited to paying customers or if there's an avenue for the general public to inquire. This is precisely why I brought my question to the Splunk forum. If you have any information on how to reach the Splunk or TruSTAR technical teams, I would greatly appreciate your guidance.

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...