Splunk Enterprise

Retention in the Cloud

Insaf
Loves-to-Learn

Hello everyone,

I have a Splunk enterprise and I am currently setting up retention for my indexes. Actually I want to know if I can storage the data after the retention period in the cloud, I mean is it possible to configure the retention in the indexes.conf file to storage the data in the cloud and how to do it?

Can anyone help me please?

Labels (2)
0 Karma

dave_null
Path Finder

Normally Splunk stores indexed data in cold buckets until the retention period expires. When that happens, Splunk moves the data to "Frozen" storage. Frozen storage can be either an archive system or just deletion.

It sounds to me like you're asking how to set up Frozen storage to store data after the retention period in Splunk.

Depending on the archiving system, there are many ways to do this. Perhaps this helps? 

https://community.splunk.com/t5/All-Apps-and-Add-ons/Frozen-archives-into-Amazon-S3/m-p/41024

https://www.splunk.com/en_us/blog/tips-and-tricks/shuttl-for-big-data-archiving.html

0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...