Splunk Search

search event even in achive data (cold etc.)

darphboubou
Explorer

Hi

 

Actualy I trying to search data even the archived ones but as you can see in printscreen below I get only the 3 last month, because I think the data older than 3 months was archived.

3months.jpg

 

Could you explain me how to retrieve data older than 3 month in my case.

 

Regards

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What is the retention period on your index - you may need to extend it beyond 3 months. Alternatively, create a report to "archive" the essential information to a summary index with a longer retention period.

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...