Dear,
The issue with the notable index, we have configured the notable index with 18 mnths retention period and also maxtotaldatasizemb to 20gb, its only used 10 % of 20gb, so as this configuration it need to have data for last 18 months but i can see last 90 days for notable index, when we checked last week its getting from 2nd july when i checked this week its getting from july 12th, so its storing only 90 days,
can you have any solution for this we are only using hot warm cold not frozen we configured the live data for 18 mnths then it will be deleted, but for notable index its only have for 90 days data nit 180 days ,
It might be misconfigured index settings. Also might be because of bucket aging and cold storage limit/availability.
Share your index settings along with storage details.
splunk cmd btool indexes list notable --debugRegards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!
The settings for "live" data are independent of those for the notable index. Please share the indexex.conf settings for the [notable] stanza.