- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How long can a windows or unix host keep logs in the Splunk agent?
BryanCaballero
New Member
04-26-2023
06:07 PM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

gcusello

SplunkTrust
04-26-2023
11:54 PM
Hi @BryanCaballero,
if you're speaking of replication of Splunk Data between Indexers, you have to implement an Indexer Cluster,. for more infos see at https://docs.splunk.com/Documentation/Splunk/9.0.4/Indexer/Basicclusterarchitecture
If you're speaking of something else, please detail your requirements.
About Data Retention, you can configure it on Indexers (or on Master Node if you have an Indexer Cluster) following the instructions in my previous answer at https://community.splunk.com/t5/Getting-Data-In/Index-Retention-Time/m-p/641540#M109402
Ciao.
Giuseppe
