Splunk Search

What is the Default bucketing time and retention policy?

splunkcol
Builder

Hello to all

I would like to know the default time set for hot, warm, cold and frozen buckets. I also want to know what the retention policy is.

When I go to "Settings" -> "Monitoring Console" -> "Indexing" -> "Indexes and Volumes" -> "Index Detail: Instance"

I find the following retention policy

splunkcol_1-1677705343091.png

When I enter the path $SPLUNK_HOME/etc/system/local/default/web.conf I can see some information about the buckets

splunkcol_2-1677705503402.png

thanks if someone can solve my question

 

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Customer Experience | Splunk 2024: New Onboarding Resources

In 2023, we were routinely reminded that the digital world is ever-evolving and susceptible to new ...

Celebrate CX Day with Splunk: Take our interactive quiz, join our LinkedIn Live ...

Today and every day, Splunk celebrates the importance of customer experience throughout our product, ...

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...