Splunk Enterprise

Why is Splunk not retaining logs beyond 90 days?

SinghK
Builder

hi All,

Though i have set frozenTimePeriodInSecs to a year on a cluster, the logs are only getting retained till 90 days max

same settings in other cluster is working fine. need some help checking the issue.

thanks in advance,

Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

First thing to check - size limit. The buckets are getting frozen when either

1) The earliest event in the bucket is oldest than the bucket age limit or

2) The data reaches maxTotalDataSizeMB limit

So even if your data is not old enough but you have enough  data to fill your index to the limit, your oldest buckets will get frozen/discarded.

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

First thing to check - size limit. The buckets are getting frozen when either

1) The earliest event in the bucket is oldest than the bucket age limit or

2) The data reaches maxTotalDataSizeMB limit

So even if your data is not old enough but you have enough  data to fill your index to the limit, your oldest buckets will get frozen/discarded.

SinghK
Builder

In my case it was maxvolumedatasizemb

 

0 Karma

SinghK
Builder

thanks @PickleRick , I will check that ..

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...