Splunk Search

index retirement policies: size versus age

ualbanytech
Path Finder

Where index retirement policies are concerned, if you define both size and age I assume first policy type hit wins?

Tags (1)
0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

That is correct, if you hit the size first, it wins. If the data becomes aged beyond what you've specified, that would win.

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

That is correct, if you hit the size first, it wins. If the data becomes aged beyond what you've specified, that would win.

ualbanytech
Path Finder

@gkanapathy, for age, does that imply that deletion may not occur until events go to frozen?

I just found: http://www.splunk.com/base/Documentation/4.1.6/admin/HowSplunkstoresindexes

and skimming it quickly--probably a mistake--it sounds like I could have newer events being added to a bucket which do not exceed my age policy and this would prevent my events from getting deleted.

However it sounds like the situation you mention should only occur in the warm buckets?

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

Thanks for the clarification.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

With the qualification that "age" is not an absolute for each item, but that items older than the specified retirement age may be deleted, as long as all items in the same bucket are also older than the retirement age.

Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...