Splunk Enterprise

Retention in the Cloud

Insaf
Loves-to-Learn

Hello everyone,

I have a Splunk enterprise and I am currently setting up retention for my indexes. Actually I want to know if I can storage the data after the retention period in the cloud, I mean is it possible to configure the retention in the indexes.conf file to storage the data in the cloud and how to do it?

Can anyone help me please?

Labels (2)
0 Karma

dave_null
Path Finder

Normally Splunk stores indexed data in cold buckets until the retention period expires. When that happens, Splunk moves the data to "Frozen" storage. Frozen storage can be either an archive system or just deletion.

It sounds to me like you're asking how to set up Frozen storage to store data after the retention period in Splunk.

Depending on the archiving system, there are many ways to do this. Perhaps this helps? 

https://community.splunk.com/t5/All-Apps-and-Add-ons/Frozen-archives-into-Amazon-S3/m-p/41024

https://www.splunk.com/en_us/blog/tips-and-tricks/shuttl-for-big-data-archiving.html

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...