- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For SmartStore with ES, which requires local disk for 90 days eq. of data, what if our retentn req is total 90 days ?s ?
dm1
Contributor
09-22-2021
03:00 AM
I am currently working on the architecture design for our Splunk platform in AWS
We have ES and are planning to leverage Smart Store for low cost data retention. I was reading through the pre-reqs of Smart Store. and one of the pre-reqs states, "For SmartStore use with Splunk Enterprise Security, confirm that you have enough local storage available to accommodate 90 days of indexed data, instead of the 30 days otherwise recommended. See Local storage requirements."
Could anyone please help with some advice on this ?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
09-22-2021
05:23 AM
90 days of local cache is not mandatory for ES. It may, however, be necessary. It depends on your datamodel accelerations. By default, many have a summary range of 3 months, which is where the 90-day recommendation comes from. If you've tuned your datamodels down then you may get away with a smaller cache.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
