Splunk Enterprise

Retention in the Cloud

Insaf
Loves-to-Learn

Hello everyone,

I have a Splunk enterprise and I am currently setting up retention for my indexes. Actually I want to know if I can storage the data after the retention period in the cloud, I mean is it possible to configure the retention in the indexes.conf file to storage the data in the cloud and how to do it?

Can anyone help me please?

Labels (2)
0 Karma

dave_null
Path Finder

Normally Splunk stores indexed data in cold buckets until the retention period expires. When that happens, Splunk moves the data to "Frozen" storage. Frozen storage can be either an archive system or just deletion.

It sounds to me like you're asking how to set up Frozen storage to store data after the retention period in Splunk.

Depending on the archiving system, there are many ways to do this. Perhaps this helps? 

https://community.splunk.com/t5/All-Apps-and-Add-ons/Frozen-archives-into-Amazon-S3/m-p/41024

https://www.splunk.com/en_us/blog/tips-and-tricks/shuttl-for-big-data-archiving.html

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...