Splunk Enterprise

Why is Splunk not retaining logs beyond 90 days?

SinghK
Builder

hi All,

Though i have set frozenTimePeriodInSecs to a year on a cluster, the logs are only getting retained till 90 days max

same settings in other cluster is working fine. need some help checking the issue.

thanks in advance,

Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

First thing to check - size limit. The buckets are getting frozen when either

1) The earliest event in the bucket is oldest than the bucket age limit or

2) The data reaches maxTotalDataSizeMB limit

So even if your data is not old enough but you have enough  data to fill your index to the limit, your oldest buckets will get frozen/discarded.

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

First thing to check - size limit. The buckets are getting frozen when either

1) The earliest event in the bucket is oldest than the bucket age limit or

2) The data reaches maxTotalDataSizeMB limit

So even if your data is not old enough but you have enough  data to fill your index to the limit, your oldest buckets will get frozen/discarded.

SinghK
Builder

In my case it was maxvolumedatasizemb

 

0 Karma

SinghK
Builder

thanks @PickleRick , I will check that ..

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...