Splunk Enterprise

Retention in the Cloud

Insaf
Loves-to-Learn

Hello everyone,

I have a Splunk enterprise and I am currently setting up retention for my indexes. Actually I want to know if I can storage the data after the retention period in the cloud, I mean is it possible to configure the retention in the indexes.conf file to storage the data in the cloud and how to do it?

Can anyone help me please?

Labels (2)
0 Karma

dave_null
Path Finder

Normally Splunk stores indexed data in cold buckets until the retention period expires. When that happens, Splunk moves the data to "Frozen" storage. Frozen storage can be either an archive system or just deletion.

It sounds to me like you're asking how to set up Frozen storage to store data after the retention period in Splunk.

Depending on the archiving system, there are many ways to do this. Perhaps this helps? 

https://community.splunk.com/t5/All-Apps-and-Add-ons/Frozen-archives-into-Amazon-S3/m-p/41024

https://www.splunk.com/en_us/blog/tips-and-tricks/shuttl-for-big-data-archiving.html

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...