Splunk Search

search event even in achive data (cold etc.)

darphboubou
Explorer

Hi

 

Actualy I trying to search data even the archived ones but as you can see in printscreen below I get only the 3 last month, because I think the data older than 3 months was archived.

3months.jpg

 

Could you explain me how to retrieve data older than 3 month in my case.

 

Regards

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What is the retention period on your index - you may need to extend it beyond 3 months. Alternatively, create a report to "archive" the essential information to a summary index with a longer retention period.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...