Splunk Enterprise

Why is Splunk not retaining logs beyond 90 days?

SinghK
Builder

hi All,

Though i have set frozenTimePeriodInSecs to a year on a cluster, the logs are only getting retained till 90 days max

same settings in other cluster is working fine. need some help checking the issue.

thanks in advance,

Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

First thing to check - size limit. The buckets are getting frozen when either

1) The earliest event in the bucket is oldest than the bucket age limit or

2) The data reaches maxTotalDataSizeMB limit

So even if your data is not old enough but you have enough  data to fill your index to the limit, your oldest buckets will get frozen/discarded.

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

First thing to check - size limit. The buckets are getting frozen when either

1) The earliest event in the bucket is oldest than the bucket age limit or

2) The data reaches maxTotalDataSizeMB limit

So even if your data is not old enough but you have enough  data to fill your index to the limit, your oldest buckets will get frozen/discarded.

SinghK
Builder

In my case it was maxvolumedatasizemb

 

0 Karma

SinghK
Builder

thanks @PickleRick , I will check that ..

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...