I have indexing data into Splunk. once the Cold bucket time period reached one month the data have to move to the frozen bucket every month. The frozen bucket is available in NAS file system. Could some one help me how to move data from cold bucket path to NAS path.
let me know in this scenario what will help
a. any script need to put ?
b. we can mention directly in index stanza it will move ?
Thanks in Advance.
We can mount the NAS storage to the OS. Please find below the url.
https://cloud.ibm.com/docs/network-attached-storage?topic=network-attached-storage-mountNASLinux
We can mount the NAS storage to the OS. Please find below the url.
https://cloud.ibm.com/docs/network-attached-storage?topic=network-attached-storage-mountNASLinux
Use frozenTimePeriodInSecs parameter in index stanza.
https://docs.splunk.com/Documentation/Splunk/8.1.1/Indexer/Setaretirementandarchivingpolicy
Hi Saravanan
I need to send data to mount point how to do it
Thanks in advance